CVE-2015-8683: Buffer Overflow
Published Apr 13, 2016
·Updated
The putcontig8bitCIELab function in tifgetimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.
Affected Software
3 affected components
LibTIFF libtiff=4.0.6
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Apr 13, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8683?
CVE-2015-8683 is classified as a denial of service vulnerability due to an out-of-bounds read.
2
How do I fix CVE-2015-8683?
To fix CVE-2015-8683, update LibTIFF to a version later than 4.0.6.
3
Who is affected by CVE-2015-8683?
Users of LibTIFF version 4.0.6 on Debian 7.0 and Debian 8.0 are affected by CVE-2015-8683.
4
What happens if CVE-2015-8683 is exploited?
If CVE-2015-8683 is exploited, it may result in a denial of service through application crashes.
5
Is CVE-2015-8683 a remote vulnerability?
Yes, CVE-2015-8683 can be exploited by remote attackers via a specially crafted TIFF image.