LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Adminframework | — | Apply OS X security update 2015-005Upgrade macOS to the latest version | Aug 28, 2015 | Aug 28, 2015 |
| Apple Osx Imageio | — | Apply OS X security update 2015-005Upgrade macOS to the latest version | Mar 29, 2016 | Mar 29, 2016 |
| Debian | — | Upgrade tiff3Upgrade tiff | Jul 30, 2024 | Feb 12, 2020 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jan 9, 2017 |
| Oracle Solaris | — | Upgrade image/library/libtiff to version 4.0.8-0.175.3.27.0.1.0 on Solaris 11.3 | Dec 19, 2017 | Dec 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 12, 2020 |
| Suse | — | Upgrade libtiff5-32bitUpgrade libtiff-develUpgrade libtiff3Upgrade libtiff-devel-32bitUpgrade libtiff3-x86Upgrade libtiff3-32bitUpgrade libtiff5Upgrade tiff | Dec 18, 2015 | Mar 31, 2015 |
| Ubuntu | — | Upgrade libtiff4Upgrade libtiff5 | Nov 8, 2024 | Feb 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub