PublicDateAtUSN: 2016-01-08 Candidate: CVE-2015-7554 PublicDate: 2016-01-08 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7554 http://www.openwall.com/lists/oss-security/2015/12/26/7 https://ubuntu.com/security/notices/USN-3212-1 https://ubuntu.com/security/notices/USN-3212-3 Description: The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image. Ubuntu-Description: Notes: mdeslaur> partial fix in RHEL sbeattie> debian incorporated partial fix in 4.0.7-7 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=809066 https://bugzilla.novell.com/show_bug.cgi?id=960341 http://bugzilla.maptools.org/show_bug.cgi?id=2564 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_tiff: vendor: https://git.centos.org/blob/rpms!libtiff.git/1ad9335dc0c1325262c62842eda01476243ec821/SOURCES!libtiff-CVE-2015-7554.patch upstream: https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06 upstream_tiff: released (4.0.7-7) precise_tiff: ignored (reached end-of-life) precise/esm_tiff: released (3.9.5-2ubuntu1.10) trusty_tiff: released (4.0.3-7ubuntu0.6) trusty/esm_tiff: released (4.0.3-7ubuntu0.6) vivid/stable-phone-overlay_tiff: ignored (reached end-of-life) vivid/ubuntu-core_tiff: DNE wily_tiff: ignored (reached end-of-life) xenial_tiff: released (4.0.6-1ubuntu0.1) esm-infra/xenial_tiff: released (4.0.6-1ubuntu0.1) yakkety_tiff: released (4.0.6-2ubuntu0.1) zesty_tiff: ignored (reached end-of-life) artful_tiff: not-affected (4.0.8-5) devel_tiff: not-affected (4.0.9-4)