First published: Thu Sep 24 2015(Updated: )
A denial of service flaw was found in the way libtiff parsed certain tiff files. An attacker could use this flaw to create a specially crafted TIFF file that would cause an application using libtiff to exhaust all available memory on the system. Original report: <a href="http://seclists.org/oss-sec/2015/q3/601">http://seclists.org/oss-sec/2015/q3/601</a>
Affected Software | Affected Version | How to fix |
---|---|---|
libtiff |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1265998 is classified as a denial of service vulnerability.
To fix REDHAT-BUG-1265998, update to the latest version of the libtiff library that addresses this vulnerability.
Applications using the libtiff library to process TIFF files are affected by REDHAT-BUG-1265998.
An attacker can create a specially crafted TIFF file that causes memory exhaustion in applications using libtiff, leading to a denial of service.
REDHAT-BUG-1265998 was reported in the third quarter of 2015.