CVE Database
/

CVE-2014-8127

Back to search

CVE-2014-8127

Published: Jun 26, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2015:0450
vendor-advisory
x_refsource_SUSE
72323
vdb-entry
x_refsource_BID
RHSA-2016:1547
vendor-advisory
x_refsource_REDHAT
GLSA-201701-16
vendor-advisory
x_refsource_GENTOO
1032760
vdb-entry
x_refsource_SECTRACK
DSA-3273
vendor-advisory
x_refsource_DEBIAN
RHSA-2016:1546
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now