PT-2014-8418 · Sam Leffler+5 · Libtiff+5

Published

2014-12-31

·

Updated

2024-06-15

·

CVE-2014-8127

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.3
Description The issue allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to various functions in different tools, including the checkInkNamesString function in tif dir.c, compresscontig function in tiff2bw.c, putcontig8bitCIELab function in tif getimage.c, LZWPreDecode function in tif lzw.c, NeXTDecode function in tif next.c, and TIFFWriteDirectoryTagLongLong8Array function in tif dirwrite.c.
Recommendations For LibTIFF version 4.0.3, consider disabling the checkInkNamesString, compresscontig, putcontig8bitCIELab, LZWPreDecode, NeXTDecode, and TIFFWriteDirectoryTagLongLong8Array functions until a patch is available. Restrict access to the thumbnail, tiff2bw, tiff2rgba, tiff2ps, tiffdither, and tiffset tools to minimize the risk of exploitation. Avoid using crafted TIFF images in these tools until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1628
CESA-2016_1546
CESA-2016_1547
CVE-2014-8127
DSA-3273-1
MGASA-2015-0112
MGASA-2016-0361
OPENSUSE-SU-2016_3035-1
OPENSUSE-SU-2024:10554-1
RHSA-2016:1546
RHSA-2016:1547
RHSA-2016_1546
RHSA-2016_1547
SUSE-SU-2015:1420-1
SUSE-SU-2015:1475-1
SUSE-SU-2015_1420-1
SUSE-SU-2015_1475-1
SUSE-SU-2016:3301-1
SUSE-SU-2016_3301-1
USN-2553-1
USN-2553-2

Affected Products

Alt Linux
Centos
Libtiff
Red Hat
Suse
Ubuntu