Vulnerability Name: | CVE-2015-8784 (CCN-110614) | ||||||||||||||||||||||||||||
Assigned: | 2016-01-24 | ||||||||||||||||||||||||||||
Published: | 2016-01-24 | ||||||||||||||||||||||||||||
Updated: | 2019-12-31 | ||||||||||||||||||||||||||||
Summary: | The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
4.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-787 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: CONFIRM Type: Issue Tracking http://bugzilla.maptools.org/show_bug.cgi?id=2508 Source: MITRE Type: CNA CVE-2015-8784 Source: CCN Type: RHSA-2016-1546 Important: libtiff security update Source: REDHAT Type: Third Party Advisory RHSA-2016:1546 Source: CCN Type: RHSA-2016-1547 Important: libtiff security update Source: REDHAT Type: Third Party Advisory RHSA-2016:1547 Source: CCN Type: oss-sec Mailing List, Sun, 24 Jan 2016 13:07:26 -0500 (EST) Re: CVE Request: tiff: potential out-of-bound write in NeXTDecode() Source: DEBIAN Type: Third Party Advisory DSA-3467 Source: CCN Type: IBM Security Bulletin T1024132 (PowerKVM) Multiple vulnerabilities in libtiff affect PowerKVM Source: CCN Type: IBM Security Bulletin T1024193 (SmartCloud Entry) Libtiff vulnerabilities affect IBM SmartClound Entry Source: MLIST Type: Mailing List [oss-security] 20160124 CVE Request: tiff: potential out-of-bound write in NeXTDecode() Source: MLIST Type: Mailing List [oss-security] 20160124 Re: CVE Request: tiff: potential out-of-bound write in NeXTDecode() Source: CONFIRM Type: Third Party Advisory http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Source: CONFIRM Type: Third Party Advisory http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Source: CONFIRM Type: Third Party Advisory http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html Source: CCN Type: LibTIFF Web site LibTIFF - TIFF Library and Utilities Source: BID Type: Third Party Advisory, VDB Entry 81696 Source: CCN Type: BID-81696 LibTIFF 'NeXTDecode()' Function Out of Bounds Write Memory Corruption Vulnerability Source: UBUNTU Type: Third Party Advisory USN-2939-1 Source: CCN Type: Red Hat Bugzilla Bug 1301652 (CVE-2015-8784) CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode() Source: XF Type: UNKNOWN libtiff-cve20158784-code-exec(110614) Source: CCN Type: LibTIFF GIT Repository libtiff/tif_next.c: fix potential out-of-bound write in NeXTDecode() Source: CONFIRM Type: Patch https://github.com/vadz/libtiff/commit/b18012dae552f85dcc5c57d3bf4e997a15b1cc1c Source: GENTOO Type: Third Party Advisory GLSA-201701-16 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8784 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration RedHat 10: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |