CVE-2015-7554: Critical severity tiff vulnerability
The TIFFVGetField function in tifdir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7554?
CVE-2015-7554 has been classified as a denial of service vulnerability that can cause crashes from invalid memory writes.
How do I fix CVE-2015-7554?
To fix CVE-2015-7554, upgrade to a patched version of libtiff that resolves this vulnerability.
What software is affected by CVE-2015-7554?
CVE-2015-7554 specifically affects libtiff version 4.0.6.
What type of attack is represented by CVE-2015-7554?
CVE-2015-7554 represents a denial of service attack where crafted TIFF image data can lead to application crashes.
Are there any potential impacts of CVE-2015-7554 beyond denial of service?
While the primary impact of CVE-2015-7554 is denial of service, it may also lead to unspecified other impacts due to potential memory corruption.