CVE-2016-5652: Libtiff
High severity, CVSS 7.0. EPSS: 4.1% chance of exploitation in the next 30 days.
An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code execution. Vulnerability can be triggered via a saved TIFF file delivered by other means.
Affected products
- Libtiff Libtiff: version 4.0.6 only
Published 2017-01-06. Last modified 2026-06-17.