libtiff: out-of-bounds read with malformed TIFF image in multiple tools
Published Jun 26, 2017
6.5
MEDIUMCVSS 3.0
EPSS 5.71%
Description
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
libtiff-0:3.9.4-18.el6_8
Fixed · RHSA-2016:1547
Red Hat Enterprise Linux 7
libtiff-0:4.0.3-25.el7_2
Fixed · RHSA-2016:1546
Red Hat Enterprise Linux 5
libtiff
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libtiff-0:3.9.4-18.el6_8 | Fixed | RHSA-2016:1547 |
| Red Hat Enterprise Linux 7 | libtiff-0:4.0.3-25.el7_2 | Fixed | RHSA-2016:1546 |
| Red Hat Enterprise Linux 5 | libtiff | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.
References (20)
- http://bugzilla.maptools.org/show_bug.cgi?id=2484 x_refsource_CONFIRMIssue Tracking
- http://bugzilla.maptools.org/show_bug.cgi?id=2485 x_refsource_CONFIRMIssue Tracking
- http://bugzilla.maptools.org/show_bug.cgi?id=2486 x_refsource_CONFIRMIssue Tracking
- http://bugzilla.maptools.org/show_bug.cgi?id=2496 x_refsource_CONFIRMIssue Tracking
- http://bugzilla.maptools.org/show_bug.cgi?id=2497 x_refsource_CONFIRMIssue Tracking
- http://bugzilla.maptools.org/show_bug.cgi?id=2500 x_refsource_CONFIRMIssue Tracking
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00022.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1546.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-1547.html vendor-advisoryx_refsource_REDHAT
- http://www.conostix.com/pub/adv/CVE-2014-8127-LibTIFF-Out-of-bounds_Reads.txt x_refsource_MISCThird Party Advisory
- http://www.debian.org/security/2015/dsa-3273 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2015/01/24/15 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/72323 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032760 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-8127 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1185805 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-7970 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-8127
- https://security.gentoo.org/glsa/201701-16 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2014-8127
Change history (0)
No recorded changes yet.