CVE-2014-9330Out-of-bounds Read in Libtiff

Severity
5.0MEDIUMNVD
OSV6.5
EPSS
1.4%
top 19.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateMay 14

Description

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDlibtiff/libtiff4.0.3
debiandebian/tiff< tiff 4.0.3-12 (bookworm)

🔴Vulnerability Details

4
GHSA
GHSA-69w2-3hr8-2mv2: Integer overflow in tif_packbits2022-05-14
OSV
tiff regression2015-04-01
OSV
tiff vulnerabilities2015-03-31
OSV
CVE-2014-9330: Integer overflow in tif_packbits2015-01-20

📋Vendor Advisories

4
Ubuntu
LibTIFF regression2015-04-01
Ubuntu
LibTIFF vulnerabilities2015-03-31
Red Hat
libtiff: Out-of-bounds reads followed by a crash in bmp2tiff2014-12-22
Debian
CVE-2014-9330: tiff - Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote att...2014

💬Community

1
Bugzilla
CVE-2014-9330 libtiff: Out-of-bounds reads followed by a crash in bmp2tiff2014-12-31