Back

MEDIUM

libtiff: out-of-bounds read with malformed TIFF image in multiple tools

Published Jun 26, 2017

Description

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 26, 2017
Updated Aug 6, 2024
Reserved Oct 10, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 7, 2014
ENISA EUVD
Assigner redhat
Published Jun 26, 2017
Updated Aug 6, 2024
Exploited since n/a
EUVD-2014-7970