VulnerabilityModified
CVE-2014-8128
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
MEDIUM 6.5EPSS 3.91%
Does this matter?
Lower severity and a low EPSS score (3.91%). Track it; it rarely justifies an emergency change on its own.
Description
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 3.91% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- libtiff/libtiff
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2015/01/24/15Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT204941Third Party Advisory
- http://support.apple.com/kb/HT204942Third Party Advisory
- http://www.conostix.com/pub/adv/CVE-2014-8128-LibTIFF-Out-of-bounds_Writes.txtThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1185812Issue Tracking, Patch, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2015/01/24/15Mailing List, Third Party Advisory
- http://support.apple.com/kb/HT204941Third Party Advisory
- http://support.apple.com/kb/HT204942Third Party Advisory
- http://www.conostix.com/pub/adv/CVE-2014-8128-LibTIFF-Out-of-bounds_Writes.txtThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1185812Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.