CVE-2016-5316: Libtiff

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.

Affected products

Published 2017-01-20. Last modified 2026-06-17.