CVE-2016-5316: Libtiff
Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.
Affected products
- Libtiff Libtiff: up to and including 4.0.6
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Opensuse Project Leap: version 42.1 only
Published 2017-01-20. Last modified 2026-06-17.