CVE-2016-5323: Libtiff

High severity, CVSS 7.5. EPSS: 6.5% chance of exploitation in the next 30 days.

The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.

Affected products

  • Libtiff Libtiff: up to and including 4.0.6
  • Opensuse Opensuse: version 13.2 only

Published 2017-01-20. Last modified 2026-06-17.