5.5
CVSSv3

CVE-2015-7313

Published: 17/03/2017 Updated: 20/03/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

LibTIFF allows remote malicious users to cause a denial of service (memory consumption and crash) via a crafted tiff file.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff -

Vendor Advisories

Debian Bug report logs - #820365 tiff: CVE-2016-3622: Division by zero in fpAcc function Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 7 Apr 2016 18:51:15 UTC Severity: important Tags: security, upstream Foun ...
Debian Bug report logs - #800124 tiff: CVE-2015-7313: OOM when parsing crafted tiff files Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 27 Sep 2015 06:42:02 UTC Severity: important Tags: security, upstream Fou ...
Debian Bug report logs - #844013 tiff: CVE-2016-9273 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 11 Nov 2016 19:51:01 UTC Severity: grave Tags: fixed-upstream, patch, security, upstream Found in versions tif ...
Debian Bug report logs - #844226 tiff: CVE-2016-9297: potential read outside buffer in _TIFFPrintField() Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 13 Nov 2016 16:09:04 UTC Severity: normal Tags: fixed-upstr ...
A denial of service flaw was found in the way libtiff parsed certain tiff files An attacker could use this flaw to create a specially crafted TIFF file that would cause an application using libtiff to exhaust all available memory on the system ...