CVE-2014-8130
published 2018-03-12CVE-2014-8130: The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero…
PriorityP427medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.90%
89.2th percentile
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| debian | tiff | < tiff 4.0.5-1 (bookworm) | tiff 4.0.5-1 (bookworm) |
| libtiff | libtiff | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibTIFF regression
vendor_ubuntu·2015-04-01·CVSS 6.5
[MEDIUM] LibTIFF regression
Title: LibTIFF regression
Summary: USN-2553-1 introduced a regression in LibTIFF.
USN-2553-1 fixed vulnerabilities in LibTIFF. One of the security fixes
caused a regression when saving certain TIFF files with a Predictor tag.
The problematic patch has been temporarily backed out until a more complete
fix is available.
We apologize for the inconvenience.
Original advisory details:
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF i
Ubuntu
LibTIFF vulnerabilities
vendor_ubuntu·2015-03-31·CVSS 6.5
CVE-2014-8127 [MEDIUM] LibTIFF vulnerabilities
Title: LibTIFF vulnerabilities
Summary: LibTIFF could be made to crash or run programs as your login if it opened a
specially crafted file.
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain
malformed BMP images. If a user or automated system were tricked into
opening a specially crafted BMP image, a remote attacker could crash the
application, leading to a denial of service. (CVE-2014-9330)
Michal Zalewsk
Red Hat
libtiff: divide by zero in the tiffdither tool
vendor_redhat·2014-12-07·CVSS 6.5
CVE-2014-8130 [MEDIUM] libtiff: divide by zero in the tiffdither tool
libtiff: divide by zero in the tiffdither tool
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
Statement: Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.
Package: libtiff (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2014-8130: tiff - The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero s...
vendor_debian·2014·CVSS 6.5
CVE-2014-8130 [MEDIUM] CVE-2014-8130: tiff - The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero s...
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
Scope: local
bookworm: resolved (fixed in 4.0.5-1)
bullseye: resolved (fixed in 4.0.5-1)
forky: resolved (fixed in 4.0.5-1)
sid: resolved (fixed in 4.0.5-1)
trixie: resolved (fixed in 4.0.5-1)
Apple
CVE-2014-8130: iOS 8.4
vendor_apple·CVSS 6.5
CVE-2014-8130 [MEDIUM] CVE-2014-8130: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2014-8130
Component: CVE-2014-8130
Apple
CVE-2014-8130: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 6.5
CVE-2014-8130 [MEDIUM] CVE-2014-8130: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2014-8130
Component: CVE-2014-8130
GHSA
GHSA-w6c9-7896-vqpm: The _TIFFmalloc function in tif_unix
ghsa_unreviewed·2022-05-14
CVE-2014-8130 [MEDIUM] CWE-369 GHSA-w6c9-7896-vqpm: The _TIFFmalloc function in tif_unix
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
OSV
CVE-2014-8130: The _TIFFmalloc function in tif_unix
osv·2018-03-12·CVSS 6.5
CVE-2014-8130 [MEDIUM] CVE-2014-8130: The _TIFFmalloc function in tif_unix
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
OSV
tiff regression
osv·2015-04-01·CVSS 6.5
[MEDIUM] tiff regression
tiff regression
USN-2553-1 fixed vulnerabilities in LibTIFF. One of the security fixes
caused a regression when saving certain TIFF files with a Predictor tag.
The problematic patch has been temporarily backed out until a more complete
fix is available.
We apologize for the inconvenience.
Original advisory details:
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain
malformed BMP images. If a user or autom
OSV
tiff vulnerabilities
osv·2015-03-31·CVSS 6.5
CVE-2014-8127 [MEDIUM] tiff vulnerabilities
tiff vulnerabilities
William Robinet discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into opening a
specially crafted image, a remote attacker could crash the application,
leading to a denial of service, or possibly execute arbitrary code with
user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129,
CVE-2014-8130)
Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain
malformed BMP images. If a user or automated system were tricked into
opening a specially crafted BMP image, a remote attacker could crash the
application, leading to a denial of service. (CVE-2014-9330)
Michal Zalewski discovered that LibTIFF incorrectly handled certain
malformed images. If a user or automated system were tricked into
No detection rules found.
No public exploits indexed.
http://bugzilla.maptools.org/show_bug.cgi?id=2483http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://openwall.com/lists/oss-security/2015/01/24/15http://rhn.redhat.com/errata/RHSA-2016-1546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1547.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.conostix.com/pub/adv/CVE-2014-8130-LibTIFF-Division_By_Zero.txthttp://www.securityfocus.com/bid/72353http://www.securitytracker.com/id/1032760https://bugzilla.redhat.com/show_bug.cgi?id=1185817https://github.com/vadz/libtiff/commit/3c5eb8b1be544e41d2c336191bc4936300ad7543https://security.gentoo.org/glsa/201701-16http://bugzilla.maptools.org/show_bug.cgi?id=2483http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://openwall.com/lists/oss-security/2015/01/24/15http://rhn.redhat.com/errata/RHSA-2016-1546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1547.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.conostix.com/pub/adv/CVE-2014-8130-LibTIFF-Division_By_Zero.txthttp://www.securityfocus.com/bid/72353http://www.securitytracker.com/id/1032760https://bugzilla.redhat.com/show_bug.cgi?id=1185817https://github.com/vadz/libtiff/commit/3c5eb8b1be544e41d2c336191bc4936300ad7543https://security.gentoo.org/glsa/201701-16
2018-03-12
Published