CVE-2014-8129
published 2018-03-12CVE-2014-8129: LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as…
PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.82%
88.9th percentile
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| debian | debian_linux | — | — |
| debian | tiff | < tiff 4.0.3-12.1 (bookworm) | tiff 4.0.3-12.1 (bookworm) |
| libtiff | libtiff | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibTIFF regression
vendor_ubuntu·2015-04-01·CVSS 6.5
[MEDIUM] LibTIFF regression
Title: LibTIFF regression
Summary: USN-2553-1 introduced a regression in LibTIFF.
USN-2553-1 fixed vulnerabilities in LibTIFF. One of the security fixes
caused a regression when saving certain TIFF files with a Predictor tag.
The problematic patch has been temporarily backed out until a more complete
fix is available.
We apologize for the inconvenience.
Original advisory details:
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF i
Ubuntu
LibTIFF vulnerabilities
vendor_ubuntu·2015-03-31·CVSS 6.5
CVE-2014-8127 [MEDIUM] LibTIFF vulnerabilities
Title: LibTIFF vulnerabilities
Summary: LibTIFF could be made to crash or run programs as your login if it opened a
specially crafted file.
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain
malformed BMP images. If a user or automated system were tricked into
opening a specially crafted BMP image, a remote attacker could crash the
application, leading to a denial of service. (CVE-2014-9330)
Michal Zalewsk
Red Hat
libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf
vendor_redhat·2014-12-07·CVSS 8.8
CVE-2014-8129 [HIGH] CWE-125 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf
libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
Statement: Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.
Package: libtiff (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2014-8129: tiff - LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bound...
vendor_debian·2014·CVSS 8.8
CVE-2014-8129 [HIGH] CVE-2014-8129: tiff - LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bound...
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
Scope: local
bookworm: resolved (fixed in 4.0.3-12.1)
bullseye: resolved (fixed in 4.0.3-12.1)
forky: resolved (fixed in 4.0.3-12.1)
sid: resolved (fixed in 4.0.3-12.1)
trixie: resolved (fixed in 4.0.3-12.1)
Apple
CVE-2014-8129: iOS 8.4
vendor_apple·CVSS 8.8
CVE-2014-8129 [HIGH] CVE-2014-8129: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2014-8129
Component: CVE-2014-8129
Apple
CVE-2014-8129: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 8.8
CVE-2014-8129 [HIGH] CVE-2014-8129: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2014-8129
Component: CVE-2014-8129
GHSA
GHSA-m6v4-297m-c926: LibTIFF 4
ghsa_unreviewed·2022-05-14
CVE-2014-8129 [HIGH] CWE-787 GHSA-m6v4-297m-c926: LibTIFF 4
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
OSV
CVE-2014-8129: LibTIFF 4
osv·2018-03-12·CVSS 8.8
CVE-2014-8129 [HIGH] CVE-2014-8129: LibTIFF 4
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
OSV
tiff regression
osv·2015-04-01·CVSS 6.5
[MEDIUM] tiff regression
tiff regression
USN-2553-1 fixed vulnerabilities in LibTIFF. One of the security fixes
caused a regression when saving certain TIFF files with a Predictor tag.
The problematic patch has been temporarily backed out until a more complete
fix is available.
We apologize for the inconvenience.
Original advisory details:
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain
malformed BMP images. If a user or autom
OSV
tiff vulnerabilities
osv·2015-03-31·CVSS 6.5
CVE-2014-8127 [MEDIUM] tiff vulnerabilities
tiff vulnerabilities
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain
malformed BMP images. If a user or automated system were tricked into
opening a specially crafted BMP image, a remote attacker could crash the
application, leading to a denial of service. (CVE-2014-9330)
Michal Zalewski discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8128 libtiff: out-of-bounds write in multiple tools
bugzilla·2015-01-26·CVSS 6.5
CVE-2014-8128 [MEDIUM] CVE-2014-8128 libtiff: out-of-bounds write in multiple tools
CVE-2014-8128 libtiff: out-of-bounds write in multiple tools
Multiple out-of-bounds writes were reported in various libtiff tools:
- CVE-2014-8128 libtiff: Out-of-bounds Write in the thumbnail tool
http://bugzilla.maptools.org/show_bug.cgi?id=2489
- CVE-2014-8128 libtiff: Out-of-bounds Write in the tiffdither tool
http://bugzilla.maptools.org/show_bug.cgi?id=2490
- CVE-2014-8128 libtiff: Out-of-bounds Write in the tiffdither tool
http://bugzilla.maptools.org/show_bug.cgi?id=2491
- CVE-2014-8128 libtiff: Out-of-bounds Write in the tiffdither tool
http://bugzilla.maptools.org/show_bug.cgi?id=2492
- CVE-2014-8128 libtiff: Out-of-bounds Write in the thumbnail and tiffcmp tools
http://bugzilla.maptools.org/show_bug.cgi?id=2493
- CVE-2014-8128 libtiff: Out-of-bounds Write in the tiff2pdf tool
Bugzilla
CVE-2014-8129 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf
bugzilla·2015-01-26·CVSS 8.8
CVE-2014-8129 [HIGH] CVE-2014-8129 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf
CVE-2014-8129 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf
Out-of-bounds read/write was reported in tiff2pdf libtiff tool:
- CVE-2014-8129 libtiff: Out-of-bounds Read & Write in the tiff2pdf tool
http://bugzilla.maptools.org/show_bug.cgi?id=2487
- CVE-2014-8129 libtiff: Out-of-bounds Read & Write in the tiff2pdf tool
http://bugzilla.maptools.org/show_bug.cgi?id=2488
Above upstream bugs were fixed by the below commits:
2014-12-21 Even Rouault
* libtiff/tif_next.c: check that BitsPerSample = 2. Fixes http://bugzilla.maptools.org/show_bug.cgi?id=2487 (CVE-2014-8129)
2014-12-21 Even Rouault
Fix various crasher bugs on fuzzed images.
* libtiff/tif_dir.c: TIFFSetField(): refuse to set negative values for TIFFTAG_XRESOLUTION and TIFFTAG_YRESOLUTION that cause asser
Bugzilla
CVE-2014-8130 libtiff: divide by zero in the tiffdither tool
bugzilla·2015-01-26·CVSS 6.5
CVE-2014-8130 [MEDIUM] CVE-2014-8130 libtiff: divide by zero in the tiffdither tool
CVE-2014-8130 libtiff: divide by zero in the tiffdither tool
Divide by zero was reported in the libtiff tiffdither tool:
- CVE-2014-8130 libtiff: Divide By Zero in the tiffdither tool
http://bugzilla.maptools.org/show_bug.cgi?id=2483
The above upstream bug was fixed by one of the commits that fix CVE-2014-8127 / CVE-2014-8128 / CVE-2014-8129
Discussion:
Patch
https://github.com/vadz/libtiff/commit/3c5eb8b1be544e41d2c336191bc4936300ad7543
libtiff/tif_unix.c
@@ -257,6 +257,9 @@ TIFFOpenW(const wchar_t* name, const char* mode)
void*
_TIFFmalloc(tmsize_t s)
{
+ if (s == 0)
+ return ((void *) NULL);
+
return (malloc((size_t) s));
}
above patch seems to suppresses this flaw
---
Statement:
Red Hat Product Security has rated this issue as having low security impact, a future update may
http://bugzilla.maptools.org/show_bug.cgi?id=2487http://bugzilla.maptools.org/show_bug.cgi?id=2488http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://openwall.com/lists/oss-security/2015/01/24/15http://rhn.redhat.com/errata/RHSA-2016-1546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1547.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.conostix.com/pub/adv/CVE-2014-8129-LibTIFF-Out-of-bounds_Reads_and_Writes.txthttp://www.securityfocus.com/bid/72352http://www.securitytracker.com/id/1032760https://bugzilla.redhat.com/show_bug.cgi?id=1185815https://security.gentoo.org/glsa/201701-16https://www.debian.org/security/2015/dsa-3273http://bugzilla.maptools.org/show_bug.cgi?id=2487http://bugzilla.maptools.org/show_bug.cgi?id=2488http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://openwall.com/lists/oss-security/2015/01/24/15http://rhn.redhat.com/errata/RHSA-2016-1546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1547.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.conostix.com/pub/adv/CVE-2014-8129-LibTIFF-Out-of-bounds_Reads_and_Writes.txthttp://www.securityfocus.com/bid/72352http://www.securitytracker.com/id/1032760https://bugzilla.redhat.com/show_bug.cgi?id=1185815https://security.gentoo.org/glsa/201701-16https://www.debian.org/security/2015/dsa-3273
2018-03-12
Published