CVE-2014-8127: Medium severity tiff vulnerability

Published Jun 26, 2017
·
Updated

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tifdir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tifgetimage.c in the tiff2rgba tool, LZWPreDecode function in tiflzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tifnext.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tifdirwrite.c in the tiffset tool.

Affected Software

4 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.3
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2

Event History

Jun 26, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2014-8127?

CVE-2014-8127 is considered a denial of service vulnerability that can potentially crash the application.

2

How do I fix CVE-2014-8127?

To fix CVE-2014-8127, you should upgrade to LibTIFF version 4.1.0 or higher as the vulnerability has been addressed in these versions.

3

What are the affected software versions for CVE-2014-8127?

CVE-2014-8127 affects LibTIFF version 4.0.3 and potentially other versions prior to 4.1.0.

4

Can CVE-2014-8127 be exploited remotely?

Yes, CVE-2014-8127 can be exploited remotely through crafted TIFF images.

5

What types of attacks are associated with CVE-2014-8127?

CVE-2014-8127 is associated with denial of service attacks that result from out-of-bounds read vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203