CVE-2014-9330: Integer Overflow
Published Jan 20, 2015
·Updated
Integer overflow in tifpackbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.3
Event History
Jan 20, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
Is CVE-2014-9330 exploitable remotely?
Yes, CVE-2014-9330 can be exploited remotely by sending specially crafted BMP images that trigger the vulnerability.