PatchSiren cyber security CVE debrief
CVE-2016-10094 Libtiff CVE debrief
CVE-2016-10094 is a high-severity LibTIFF issue in the tiff2pdf path. The vulnerability is described as an off-by-one error in t2p_readwrite_pdf_image_tile in tools/tiff2pdf.c in LibTIFF 4.0.7, triggered by a crafted image. NVD rates the record at CVSS 7.8, reflecting potentially serious confidentiality, integrity, and availability impact if exploitation succeeds.
- Vendor
- Libtiff
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-01
- Advisory updated
- 2026-05-13
Who should care
Administrators, packaging teams, and application owners using LibTIFF 4.0.7—especially any workflow that processes untrusted TIFF input or uses tiff2pdf to convert images—should review exposure and apply the available fix or vendor backport.
Technical summary
The NVD record identifies a CWE-189 numeric/off-by-one style weakness in LibTIFF 4.0.7, specifically in t2p_readwrite_pdf_image_tile inside tools/tiff2pdf.c. The documented trigger is a crafted image. The corpus includes a CVSS 3.0 vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, so NVD indicates user interaction is required even though the short description says remote attackers may be able to trigger the bug.
Defensive priority
High
Recommended defensive actions
- Inventory systems that ship or embed LibTIFF 4.0.7, including image conversion pipelines that call tiff2pdf.
- Apply the upstream fix or a trusted vendor backport corresponding to the referenced libtiff patch commit.
- Restrict processing of untrusted image files and isolate conversion jobs in sandboxes or low-privilege environments.
- Review downstream advisories and package updates from your distribution, including the Debian and Gentoo references in the corpus.
Evidence notes
Primary evidence comes from the NVD record and its linked references. The corpus ties the flaw to Bugzilla issue 2640, an upstream patch commit in the libtiff repository, and third-party advisories from Debian, Gentoo, and OSS-security. One important nuance is that the short description says 'remote attackers,' while the NVD CVSS vector includes UI:R; this debrief preserves both statements without reconciling beyond the supplied sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10094 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10094
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10094 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10094
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/vadz/libtiff/commit/c7153361a4041260719b340f73f2f76
[email protected] - Exploit, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.