CVE-2016-5314 - log back

CVE-2016-5314 created at 25 Sep 2019 19:31:40
Severity
+ High
Remote
+ Local
Type
+ Arbitrary code execution
Description
+ A vulnerability was found in libtiff. A maliciously crafted TIFF file could cause the application to crash when using rgb2ycbcr command via an out-of-bounds write in the PixarLogDecode() function.
References
+ http://www.openwall.com/lists/oss-security/2016/06/15/1
+ http://bugzilla.maptools.org/show_bug.cgi?id=2554
+ https://github.com/vadz/libtiff/commit/391e77fcd217e78b2c51342ac3ddb7100ecacdd2
Notes
+ Reproducer http://bugzilla.maptools.org/attachment.cgi?id=654
+ rgb2ycbcr tool removed upstream in 4.0.7