CVE-2016-5317: Libtiff
Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.
Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.
Affected products
- Libtiff Libtiff: version 4.0.6 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Opensuse Project Leap: version 42.1 only
Published 2017-01-20. Last modified 2026-06-17.