CVE-2016-3619: Libtiff

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

Affected products

  • Libtiff Libtiff: version 4.0.6 only

Published 2016-10-03. Last modified 2026-06-17.