Netskope Threat Labs

FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt

IPS-SWG

1 SID: 39607

First seen
July 2024
Last seen
February 2026

Detects images exploiting CVE-2016-4631, CVE-2016-5875, and CVE-2017-2870, buffer overflows in TIFF tile size handling across multiple products that can allow code execution. The rule matches the crafted tile dimensions that public exploits use to overflow the image parser.