PublicDateAtUSN: 2014-12-31 Candidate: CVE-2014-8129 PublicDate: 2018-03-12 02:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8129 http://www.conostix.com/pub/adv/CVE-2014-8129-LibTIFF-Multiple_Out-of-bounds_Reads_and_Writes.txt https://ubuntu.com/security/notices/USN-2553-1 Description: LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776185 http://bugzilla.maptools.org/show_bug.cgi?id=2487 (tiff2pdf) http://bugzilla.maptools.org/show_bug.cgi?id=2488 (tiff2pdf) Priority: medium Discovered-by: William Robinet Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_tiff: upstream: https://github.com/vadz/libtiff/commit/cd82b5267ad4c10eb91e4ee8a716a81362cf851c (2487) upstream: https://github.com/vadz/libtiff/commit/662f74445b2fea2eeb759c6524661118aef567ca (2488) upstream_tiff: needs-triage lucid_tiff: released (3.9.2-2ubuntu0.15) precise_tiff: released (3.9.5-2ubuntu1.7) trusty_tiff: released (4.0.3-7ubuntu0.2) trusty/esm_tiff: released (4.0.3-7ubuntu0.2) utopic_tiff: released (4.0.3-10ubuntu0.1) devel_tiff: released (4.0.3-12.3ubuntu1)