Candidate: CVE-2015-8870 PublicDate: 2016-12-06 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8870 http://download.osgeo.org/libtiff/tiff-4.0.4.tar.gz http://www.floyd.ch/?p=874BMP Description: Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file. Ubuntu-Description: Notes: mdeslaur> upstream removed the bmp2tiff utility in 4.0.7 mdeslaur> fixed by CVE-2014-81xx-1.patch in Ubuntu Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H [7.4 HIGH] Patches_tiff: vendor: https://git.centos.org/blob/rpms!libtiff.git/70f9f0cf3d31e314263d286a0ff78b3947810abf/SOURCES!libtiff-CVE-2015-8870.patch upstream: https://github.com/vadz/libtiff/commit/0289b27c5d4dc928471962a6dba478cb69e4f15c upstream_tiff: needs-triage precise_tiff: not-affected (3.9.5-2ubuntu1.9) precise/esm_tiff: not-affected (3.9.5-2ubuntu1.9) trusty_tiff: not-affected (4.0.3-7ubuntu0.4) trusty/esm_tiff: not-affected (4.0.3-7ubuntu0.4) vivid/stable-phone-overlay_tiff: ignored (reached end-of-life) vivid/ubuntu-core_tiff: DNE xenial_tiff: not-affected (4.0.6-1) esm-infra/xenial_tiff: not-affected (4.0.6-1) yakkety_tiff: not-affected (4.0.6-2) zesty_tiff: not-affected devel_tiff: not-affected