LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.conostix.com/pub/adv/CVE-2014-8128-LibTIFF-Out-of-bounds_Writes.txt | third party advisory |
http://openwall.com/lists/oss-security/2015/01/24/15 | third party advisory mailing list |
http://support.apple.com/kb/HT204941 | third party advisory |
http://support.apple.com/kb/HT204942 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1185812 | patch third party advisory issue tracking |
http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.html | third party advisory mailing list |
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html | third party advisory mailing list |