cve/2014/CVE-2014-9655.md
2024-05-26 14:27:05 +02:00

868 B

CVE-2014-9655

Description

The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif.

POC

Reference

Github

No PoCs found on GitHub currently.