CVE-2015-7313: Medium severity tiff vulnerability
A denial of service flaw was found in the way libtiff parsed certain tiff files. An attacker could use this flaw to create a specially crafted TIFF file that would cause an application using libtiff to exhaust all available memory on the system.
Original report:
http://seclists.org/oss-sec/2015/q3/601
Other sources
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7313?
CVE-2015-7313 has been classified as a denial of service vulnerability that can cause applications using libtiff to exhaust available memory.
How do I fix CVE-2015-7313?
To address CVE-2015-7313, update libtiff to version 4.2.0-1+deb11u5, 4.2.0-1+deb11u6, 4.5.0-6+deb12u2, 4.5.0-6+deb12u1, 4.7.0-3, or 4.7.0-5.
What types of applications are affected by CVE-2015-7313?
Applications that utilize the libtiff library for processing TIFF files are affected by CVE-2015-7313.
Can CVE-2015-7313 be exploited remotely?
Yes, CVE-2015-7313 can potentially be exploited remotely if a user opens a specially crafted TIFF file from an untrusted source.
What versions of libtiff are vulnerable to CVE-2015-7313?
Versions of libtiff prior to 4.2.0 are vulnerable to CVE-2015-7313.