Out-of-bounds write in LibTIFF - CVE-2015-7554

 

Out-of-bounds write in LibTIFF - CVE-2015-7554

Published: July 1, 2016 / Updated: July 18, 2017


Vulnerability identifier: #VU3801
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7554
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error in _TIFFVGetField() function in tif_dir.c in libtiff 4.0.6. A remote attacker can create a specially crafted TIFF image, trick the victim into opening it and execute arbitrary code on the target system.

Affected software

LibTIFF
Arch Linux
tiff (Alpine package)
Dynamic System Analysis (DSA) Preboot

How to mitigate CVE-2015-7554

Update to version 4.0.7.

tiff (Alpine package) - update to 4.0.6-r2
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65

External References

Related Security Bulletins