CVE-2016-3633
Publication date 3 October 2016
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src variable.
Notes
mdeslaur
upstream removed the thumbnail utility in 4.0.7 DoS in thumbnail tool we will not be fixing this minor issue, marking as ignored
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |