PT-2015-3231 · Libtiff+4 · Libtiff+4

Lmx

·

Published

2015-12-31

·

Updated

2024-06-15

·

CVE-2015-8665

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.6
Description The issue is caused by a buffer overflow in the tif getimage.c file of the LibTIFF library. It can be exploited by a remote attacker to cause a denial of service, specifically an out-of-bounds read, by using the SamplesPerPixel tag in a TIFF image.
Recommendations For LibTIFF version 4.0.6, consider restricting the use of the tif getimage.c function until a patch is available, or avoid using the SamplesPerPixel tag in TIFF images to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01126
CESA-2016_1546
CESA-2016_1547
CVE-2015-8665
DLA-402-1
DLA-610-1
DSA-3467-1
MGASA-2016-0017
OPENSUSE-SU-2016_3035-1
OPENSUSE-SU-2024:10554-1
RHSA-2016:1546
RHSA-2016:1547
RHSA-2016_1546
RHSA-2016_1547
SUSE-SU-2022:14888-1
SUSE-SU-2022_14888-1
USN-2939-1

Affected Products

Centos
Libtiff
Red Hat
Suse
Ubuntu