PT-2015-3229 · None+4 · Libtiff+4

Even Rouault

·

Publicado

2015-12-31

·

Atualizado

2019-12-31

·

CVE-2015-8784

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF (affected versions not specified)
Description The issue is related to the NeXTDecode function in the tif next.c file of LibTIFF, which allows remote attackers to cause a denial of service due to an out-of-bounds write. This can be achieved by using a crafted TIFF image. The problem stems from a buffer overflow in the NeXTDecode function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1628
BDU:2016-01124
CESA-2016_1546
CESA-2016_1547
CVE-2015-8784
DLA-405-1
DLA-880-1
DSA-3467-1
RHSA-2016:1546
RHSA-2016:1547
RHSA-2016_1546
RHSA-2016_1547
USN-2939-1

Produtos afetados

Alt Linux
Centos
Libtiff
Red Hat
Ubuntu