CVE-2014-8127: Medium severity tiff vulnerability
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tifdir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tifgetimage.c in the tiff2rgba tool, LZWPreDecode function in tiflzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tifnext.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tifdirwrite.c in the tiffset tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8127?
CVE-2014-8127 is considered a denial of service vulnerability that can potentially crash the application.
How do I fix CVE-2014-8127?
To fix CVE-2014-8127, you should upgrade to LibTIFF version 4.1.0 or higher as the vulnerability has been addressed in these versions.
What are the affected software versions for CVE-2014-8127?
CVE-2014-8127 affects LibTIFF version 4.0.3 and potentially other versions prior to 4.1.0.
Can CVE-2014-8127 be exploited remotely?
Yes, CVE-2014-8127 can be exploited remotely through crafted TIFF images.
What types of attacks are associated with CVE-2014-8127?
CVE-2014-8127 is associated with denial of service attacks that result from out-of-bounds read vulnerabilities.