PT-2015-3229 · None+4 · Libtiff+4

Even Rouault

·

Published

2015-12-31

·

Updated

2019-12-31

·

CVE-2015-8784

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF (affected versions not specified)
Description The issue is related to the NeXTDecode function in the tif next.c file of LibTIFF, which allows remote attackers to cause a denial of service due to an out-of-bounds write. This can be achieved by using a crafted TIFF image. The problem stems from a buffer overflow in the NeXTDecode function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1628
BDU:2016-01124
CESA-2016_1546
CESA-2016_1547
CVE-2015-8784
DLA-405-1
DLA-880-1
DSA-3467-1
RHSA-2016:1546
RHSA-2016:1547
RHSA-2016_1546
RHSA-2016_1547
USN-2939-1

Affected Products

Alt Linux
Centos
Libtiff
Red Hat
Ubuntu