First published: Fri Jan 08 2016(Updated: )
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
libtiff | =4.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7554 has been classified as a denial of service vulnerability that can cause crashes from invalid memory writes.
To fix CVE-2015-7554, upgrade to a patched version of libtiff that resolves this vulnerability.
CVE-2015-7554 specifically affects libtiff version 4.0.6.
CVE-2015-7554 represents a denial of service attack where crafted TIFF image data can lead to application crashes.
While the primary impact of CVE-2015-7554 is denial of service, it may also lead to unspecified other impacts due to potential memory corruption.