CVE-2015-1547: Buffer Overflow
Published Apr 13, 2016
·Updated
The NeXTDecode function in tifnext.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.
Affected Software
3 affected components
Debian Debian Linux=7.0
Debian Debian Linux=8.0
LibTIFF libtiff<=4.0.6
Event History
Apr 13, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1547?
CVE-2015-1547 is classified as a denial of service vulnerability.
2
How do I fix CVE-2015-1547?
To fix CVE-2015-1547, update LibTIFF to a version later than 4.0.6.
3
What software is affected by CVE-2015-1547?
CVE-2015-1547 affects LibTIFF versions up to and including 4.0.6 and Debian Linux versions 7.0 and 8.0.
4
What type of attack does CVE-2015-1547 facilitate?
CVE-2015-1547 allows remote attackers to cause a denial of service via crafted TIFF images.
5
What is the impact of exploiting CVE-2015-1547?
Exploiting CVE-2015-1547 can result in uninitialized memory access, leading to potential application crashes.