CVE-2014-9655: Buffer Overflow
The (1) putcontig8bitYCbCr21tile function in tifgetimage.c or (2) NeXTDecode function in tifnext.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9655?
CVE-2014-9655 has been classified as a denial of service vulnerability.
How do I fix CVE-2014-9655?
To fix CVE-2014-9655, update to a non-vulnerable version of the LibTIFF package such as 4.1.0+git191117-2~deb10u4 or later.
Which systems are affected by CVE-2014-9655?
CVE-2014-9655 affects various versions of the LibTIFF library and Debian Linux systems.
Can CVE-2014-9655 be exploited remotely?
Yes, CVE-2014-9655 can be exploited remotely through specially crafted TIFF images.
What components of LibTIFF are involved in CVE-2014-9655?
The vulnerability in CVE-2014-9655 is related to the putcontig8bitYCbCr21tile function in tif_getimage.c and the NeXTDecode function in tif_next.c.