Vulnerability & Exploit Database

Back to search

Oracle Solaris 11: CVE-2014-9655: Vulnerability in LibTIFF

Severity CVSS Published Added Modified
4 (AV:N/AC:M/Au:N/C:N/I:N/A:P) April 12, 2016 May 28, 2017 January 07, 2018

Description

The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif.

Free Nexpose Download

Discover, prioritize, and remediate security risks today!

 Download now

References

Solution

oracle-solaris-11-3-upgrade-image-library-libtiff-3-9-5-0-175-3-9-0-3-0

Related Vulnerabilities