CVE-2016-1547
published 2017-01-06CVE-2016-1547: An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec…
PriorityP434medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
5.11%
91.5th percentile
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p7+dfsg-1 (bullseye) | ntp 1:4.2.8p7+dfsg-1 (bullseye) |
| debian | ntp | < ntp 1:4.2.8p8+dfsg-1 (bullseye) | ntp 1:4.2.8p8+dfsg-1 (bullseye) |
| novell | suse_manager | — | — |
| ntp | ntp | <= 4.2.8 | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p7+dfsg-1 | 1:4.2.8p7+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.8p8+dfsg-1 | 1:4.2.8p8+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-3ubuntu5.3 | 1:4.2.8p4+dfsg-3ubuntu5.3 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | manager_proxy | — | — |
| suse | openstack_cloud | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
vendor_cisco5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
CISA ICS
Siemens TIM 4R-IE Devices
cisa_ics·2021-04-13·CVSS 7.5
[HIGH] Siemens TIM 4R-IE Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens TIM 4R-IE Devices
Last RevisedApril 13, 2021
Alert CodeICSA-21-103-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: TIM 4R-IE
- Vulnerabilities: Incorrect Type Conversion or Cast, Improper Input Validation, Improper Authentication, Security Features, Null Pointer Dereference, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Race Condition
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could compromise the confidentiality, integri
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker cou
Red Hat
libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
vendor_redhat·2016-06-15·CVSS 8.8
CVE-2016-5320 [HIGH] CWE-787 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2016-5314. Note: All CVE users should reference CVE-2016-5314 instead of this candidate.
Statement: Also, please note that, this issue has already been addressed in Red Hat Enterprise Linux 6 via RHSA-2016:1547 and in Red Hat Enterprise Linux 7 via RHSA-2016:1546 as listed under affected packages and Security Errata.
Package: libtiff (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-libtiff3 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
vendor_redhat·2016-06-02·CVSS 5.3
CVE-2016-4957 [MEDIUM] ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
Statement: This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they did not include the same upstream fix for CVE-2016-1547 that introduced the issue. The fix developed by Red Hat for CVE-2016-1547 did not include this issue.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Linux 7) - Not affected
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-04-29·CVSS 5.3
CVE-2016-1547 [MEDIUM] FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:16.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-04-29
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-04-27 15:24:33 UTC (stable/10, 10.3-STABLE)
2016-04-29 08:02:31 UTC (releng/10.3, 10.3-RELEASE-p1)
2016-04-29 08:02:31 UTC (releng/10.2, 10.2-RELEASE-p15)
2016-04-29 08:02:31 UTC (releng/10.1, 10.1-RELEASE-p32)
2016-04-27 15:25:18 UTC (stable/9, 9.3-STABLE)
2016-04-29 08:02:31 UTC (releng/9.3, 9.3-RELEASE-p40)
CVE Name: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550,
CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518,
CVE-2016-2519
For general information regarding FreeBSD Security Advisorie
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco·2016-04-28·CVSS 5.3
CVE-2015-7704 [MEDIUM] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details 11 issues regarding DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a system's time. Two of the vulnerabilities disclosed in the NTP security notice address issues that
Red Hat
ntp: crypto-NAK preemptable association denial of service
vendor_redhat·2016-04-26·CVSS 5.3
CVE-2016-1547 [MEDIUM] ntp: crypto-NAK preemptable association denial of service
ntp: crypto-NAK preemptable association denial of service
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
A denial of service flaw was found in the way NTP handled preemptable client associations. A remote attacker could send several crypto NAK packets to a victim client, each with a spoofed source address of an existing associated peer, preventing that client from synchronizing its time.
Package: ntp (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-1547: ntp - An off-path attacker can cause a preemptible client association to be demobilize...
vendor_debian·2016·CVSS 5.3
CVE-2016-1547 [MEDIUM] CVE-2016-1547: ntp - An off-path attacker can cause a preemptible client association to be demobilize...
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
Debian
CVE-2016-4957: ntp - ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service ...
vendor_debian·2016·CVSS 5.3
CVE-2016-4957 [MEDIUM] CVE-2016-4957: ntp - ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service ...
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco
CVE-2016-1547 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
CVE-2016-1547: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz44082, CSCuz44085, CSCuz44088, CSCuz44082, CSCuz44085
GHSA
GHSA-3mq4-x52h-fcwc: ntpd in NTP before 4
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2016-4957 [MEDIUM] CWE-476 GHSA-3mq4-x52h-fcwc: ntpd in NTP before 4
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
GHSA
GHSA-hqqw-v32x-33cf: An off-path attacker can cause a preemptible client association to be demobilized in NTP 4
ghsa_unreviewed·2022-05-13
CVE-2016-1547 [MEDIUM] CWE-20 GHSA-hqqw-v32x-33cf: An off-path attacker can cause a preemptible client association to be demobilized in NTP 4
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
OSV
CVE-2016-1547: An off-path attacker can cause a preemptible client association to be demobilized in NTP 4
osv·2017-01-06·CVSS 5.3
CVE-2016-1547 [MEDIUM] CVE-2016-1547: An off-path attacker can cause a preemptible client association to be demobilized in NTP 4
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
OSV
ntp vulnerabilities
osv·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker could possibly use this
issue to overwrite arbitrary files. (CV
OSV
CVE-2016-4957: ntpd in NTP before 4
osv·2016-07-05·CVSS 5.3
CVE-2016-4957 [MEDIUM] CVE-2016-4957: ntpd in NTP before 4
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
No detection rules found.
No public exploits indexed.
Fortinet
Analysis of Vulnerability CVE-2016-4957 in NTPD
blogs_fortinet·2016-06-20·CVSS 5.3
CVE-2016-4957 [MEDIUM] Analysis of Vulnerability CVE-2016-4957 in NTPD
FORTIGUARD LABS THREAT RESEARCH
Analysis of Vulnerability CVE-2016-4957 in NTPD
By Dehui Yin | June 20, 2016
The Network Time Protocol Daemon (NTPD) by NTP.org, runs on *nix operation systems. It sets and maintains system time in synchronization with internet standard time servers or local reference clocks. NTPD is shipped with many major server operating systems, routers, and infrastructure devices.
CVE-2016-4957 is a high severity vulnerability targeted at the NTPD. It causes a segfault event that causes NTPD to close. If the NTP service stops, it can affect many time-sensitive programs, such as database operations and server groups which need NTP to synchronize time with each other.
The ntp-4.2.8p8 update was released on Jun 02, 2016 to address this vulnerability, along with several
Talos
Vulnerability Spotlight: Further NTPD Vulnerabilities
blogs_talos·2016-04-27·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: Further NTPD Vulnerabilities
## Vulnerability Spotlight: Further NTPD Vulnerabilities
As a member of the Linux Foundation Core Infrastructure Initiative , Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon (ntpd) for security defects. We previously identified a series of vulnerabilities in the Network Time Protocol daemon; through our continued research we have identified further vulnerabilities in the software.
Since 2013, criminals have been abusing NTP packets in order to cause amplified denial of service attacks . The ubiquity of the Network Time Protocol daemon and the importance of co-ordinated time for the correct functioning of many services means that it is a tempting target for attack. Vulnerabilities that allow the time as understood by ntpd to be altered can be used by
Talos
Vulnerability Spotlight: Further NTPD Vulnerabilities
blogs_talos·2016-04-27·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: Further NTPD Vulnerabilities
As a member of the Linux Foundation Core Infrastructure Initiative, Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon (ntpd) for security defects. We previously identified a series of vulnerabilities in the Network Time Protocol daemon; through our continued research we have identified further vulnerabilities in the software.
Since 2013, criminals have been abusing NTP packets in order to cause amplified denial of service attacks. The ubiquity of the Network Time Protocol daemon and the importance of co-ordinated time for the correct functioning of many services means that it is a tempting target for attack. Vulnerabilities that allow the time as understood by ntpd to be altered can be used by attackers to set the time to an arbitrary value. This allow
Bugzilla
CVE-2016-5320 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
bugzilla·2016-06-15·CVSS 8.8
CVE-2016-5320 [HIGH] CVE-2016-5320 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
CVE-2016-5320 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
A vulnerability was found in libtiff. A maliciously crafted TIFF file could cause the application to crash or even enable RCE on vulnerable machine when using rgb2ycbcr command.
References:
http://seclists.org/oss-sec/2016/q2/551
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1346699]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1346700]
Affects: epel-7 [bug 1346701]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RH
Bugzilla
CVE-2016-4953 ntp: bad authentication demobilizes ephemeral associations
bugzilla·2016-05-30·CVSS 7.5
CVE-2016-4953 [HIGH] CVE-2016-4953 ntp: bad authentication demobilizes ephemeral associations
CVE-2016-4953 ntp: bad authentication demobilizes ephemeral associations
It was found that the fixes for CVE-2015-7979 and CVE-2016-1547 were incomplete: An attacker can send a spoofed packet that contains an invalid MAC to a client/peer and demobilize its ephemeral association.
Discussion:
Acknowledgments:
Name: Miroslav Lichvar (Red Hat)
---
Statement:
This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.
---
Upstream bug:
http://support.ntp.org/bin/view/Main/NtpBug3045
Externa
Bugzilla
CVE-2016-4957 ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
bugzilla·2016-05-30·CVSS 5.3
CVE-2016-4957 [MEDIUM] CVE-2016-4957 ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
CVE-2016-4957 ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
It was found that the fix for CVE-2016-1547 introduced a new issue. An attacker could send a crafted packet with crypto-NAK to a server or client that will cause ntpd to crash (segfault on NULL pointer dereference).
The issue was introduced in the original patch for CVE-2016-1547 here:
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=56b42514rgZyUCPCWq2Uyhw4BWUpSg
Discussion:
Acknowledgments:
Name: CERT/CC
Upstream: Nicolas Edet (Cisco)
---
Statement:
This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they did not include the same upstream fix for CVE-2016-1547 that introduced the issue. The fix developed by Red Hat for CVE-2016-1547 did not include this issue.
---
Bugzilla
CVE-2016-1547 ntp: crypto-NAK preemptable association denial of service
bugzilla·2016-04-28·CVSS 7.5
CVE-2016-1547 [HIGH] CVE-2016-1547 ntp: crypto-NAK preemptable association denial of service
CVE-2016-1547 ntp: crypto-NAK preemptable association denial of service
The following flaw was found in NTP:
An off-path attacker can cause a preemptable client association to be demobilized by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
Furthermore, if the attacker keeps sending crypto NAK packets, for example every one second, the victim never has a chance to reestablish the association and synchronize time with the legitimate server.
Upstream bugs:
http://support.ntp.org/bin/view/Main/NtpBug3007
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security
http://www.talosintel.com/reports/TALOS-2016-0081/
Discussion:
In Fed
Bugzilla
CVE-2016-3632 libtiff: out-of-bounds write in _TIFFVGetField function
bugzilla·2016-04-08·CVSS 7.8
CVE-2016-3632 [HIGH] CVE-2016-3632 libtiff: out-of-bounds write in _TIFFVGetField function
CVE-2016-3632 libtiff: out-of-bounds write in _TIFFVGetField function
Out-of-bounds write vulnerability was found in _TIFFVGetField function in tif_dirinfo.c, allowing attacker to cause a denial of service or command execution via a crafted TIFF image.
Vulnerable code:
libtiff/tif_dir.c:1073
1068 if (fip->field_type == TIFF_ASCII
1069 || fip->field_readcount == TIFF_VARIABLE
1070 || fip->field_readcount == TIFF_VARIABLE2
1071 || fip->field_readcount == TIFF_SPP
1072 || tv->count > 1) {
1073 *va_arg(ap, void **) = tv->value;
1074 ret_val = 1;
Public via:
http://seclists.org/oss-sec/2016/q2/33
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2549
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn
Bugzilla
CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool
bugzilla·2016-04-08·CVSS 7.8
CVE-2016-3945 [HIGH] CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool
CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool
Out-of-bounds write vulnerability was found in cvt_by_strip and cvt_by_tile functions in tiff2rgba, allowing attacker to cause a denial of service or command execution via a crafted TIFF image.
Public via:
http://seclists.org/oss-sec/2016/q2/30
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2545
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
---
It would have been good to attach your patch to the upstream bug instead of letting l
Bugzilla
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
bugzilla·2016-01-25·CVSS 6.5
CVE-2015-8784 [MEDIUM] CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
A flaw was discovered in a way libtiff decodes special data. A potential out-of-bounds write could occur for specifically crafted images.
External bug report:
http://bugzilla.maptools.org/show_bug.cgi?id=2508
CVE assignment:
http://seclists.org/oss-sec/2016/q1/191
Upstream fix:
https://github.com/vadz/libtiff/commit/b18012dae552f85dcc5c57d3bf4e997a15b1cc1c
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1301653]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://r
Bugzilla
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8665 [MEDIUM] CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
An Out-of-bounds read flaw was found in libtiff. An attacker could create a specially-crafted TIFF file, which could cause libtiff to crash.
Reference:
http://www.openwall.com/lists/oss-security/2015/12/24/4
Discussion:
Please inform me when you will have a patch or at least a reference for the bugzilla.
Greetings
Petr
---
Patch for this and bug#1294427:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/
Bugzilla
CVE-2015-8668 libtiff: OOB read in bmp2tiff
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-8668 [CRITICAL] CVE-2015-8668 libtiff: OOB read in bmp2tiff
CVE-2015-8668 libtiff: OOB read in bmp2tiff
A heap-buffer oveflow was found in bmp2tiff, A tool used to created TIFF format files from BMP format image files. An attacker could provide a specially-crafted BMP format file, which when converted to TIFF format, using the bmp2tiff tool, could lead to bmp2tiff executable to crash.
Reference:
http://seclists.org/bugtraq/2015/Dec/138
Discussion:
I haven't completed my analysis yet, but for now I tend to say that this is only OOB read.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-
Bugzilla
CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8683 [MEDIUM] CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
An out-bounds-read flaw was found in the way libtiff processed CIE Lab image format files. A attacker could create a specially-crafted CIE Lab image format files which could cause libtiff to crash.
Reference:
http://seclists.org/oss-sec/2015/q4/583
Discussion:
Patch for this and bug#1294444:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
Bugzilla
CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-7554 [CRITICAL] CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
An Invalid memory write flaw was found in libtiff in the way it parsed certain extension tags when reading TIFF format files. An attacker could use this flaw to crash or even execute arbitrary code with the permission of the user running such an application compiled against libtiff.
Reference:
http://seclists.org/bugtraq/2015/Dec/137
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
---
*** Bug 1410063 has been marked as
http://rhn.redhat.com/errata/RHSA-2016-1552.htmlhttp://www.debian.org/security/2016/dsa-3629http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/88276http://www.securitytracker.com/id/1035705http://www.talosintelligence.com/reports/TALOS-2016-0081/https://access.redhat.com/errata/RHSA-2016:1141https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://www.arista.com/en/support/advisories-notices/security-advisories/1332-security-advisory-19http://rhn.redhat.com/errata/RHSA-2016-1552.htmlhttp://www.debian.org/security/2016/dsa-3629http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/88276http://www.securitytracker.com/id/1035705http://www.talosintelligence.com/reports/TALOS-2016-0081/https://access.redhat.com/errata/RHSA-2016:1141https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://www.arista.com/en/support/advisories-notices/security-advisories/1332-security-advisory-19
2017-01-06
Published