Number: AV16-176
Date: 31 October 2016
Purpose
The purpose of this advisory is to bring attention to LibTIFF security patches.
Assessment
Security patches released for LibTIFF which address multiple vulnerabilities. Exploitation of these vulnerabilities may allow for arbitrary remote code execution. The LibTIFF library is included with and leveraged by several hardware and software products. Please note, CVE-2016-8331 remains unpatched.
Affected Versions: LibTIFF 4.0.6 and prior
CVE References: CVE-2016-5652, CVE-2016-5875, CVE-2016-8331
Suggested Action
CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization’s critical services, and follow their patch management process accordingly.
References:
Cisco Talos (vulnerability report):
http://blog.talosintel.com/2016/10/LibTIFF-Code-Execution.html
LibTIFF:
http://www.simplesystems.org/libtiff/
LibTIFF Git Repository:
https://github.com/vadz/libtiff