CVE-2014-8129Out-of-bounds Write in Libtiff

Severity
8.8HIGHNVD
OSV6.5
EPSS
1.5%
top 19.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMay 14

Description

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDlibtiff/libtiff4.0.3
NVDapple/mac_os_x6 versions+5

Also affects: Debian Linux 7.0, Enterprise Linux 7.2, 7.3, 7.4

Patches

🔴Vulnerability Details

5
GHSA
GHSA-m6v4-297m-c926: LibTIFF 42022-05-14
OSV
CVE-2014-8129: LibTIFF 42018-03-12
CVEList
CVE-2014-8129: LibTIFF 42018-03-12
OSV
tiff regression2015-04-01
OSV
tiff vulnerabilities2015-03-31

📋Vendor Advisories

6
Ubuntu
LibTIFF regression2015-04-01
Ubuntu
LibTIFF vulnerabilities2015-03-31
Red Hat
libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf2014-12-07
Debian
CVE-2014-8129: tiff - LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bound...2014
Apple
CVE-2014-8129: iOS 8.4

💬Community

3
Bugzilla
CVE-2014-8128 libtiff: out-of-bounds write in multiple tools2015-01-26
Bugzilla
CVE-2014-8129 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf2015-01-26
Bugzilla
CVE-2014-8130 libtiff: divide by zero in the tiffdither tool2015-01-26
CVE-2014-8129 — Out-of-bounds Write in Libtiff | cvebase