CVE-2015-8784Out-of-bounds Write in Libtiff

Severity
6.5MEDIUMNVD
EPSS
1.5%
top 18.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 13

Description

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff< 4.0.7
debiandebian/tiff< tiff 4.0.6-1 (bookworm)

Also affects: Debian Linux 7.0, 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gw6g-3r38-pg33: The NeXTDecode function in tif_next2022-05-13
OSV
CVE-2015-8784: The NeXTDecode function in tif_next2016-04-13

📋Vendor Advisories

3
Ubuntu
LibTIFF vulnerabilities2016-03-23
Red Hat
libtiff: out-of-bound write in NeXTDecode()2016-01-24
Debian
CVE-2015-8784: tiff - The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to caus...2015

💬Community

2
Bugzilla
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()2016-01-25
Bugzilla
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode() [fedora-all]2016-01-25