The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.
References
Configurations
Information
Published : 2016-01-08 11:59
Updated : 2018-10-30 09:27
NVD link : CVE-2015-7554
Mitre link : CVE-2015-7554
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
libtiff
- libtiff