Skip to main content

Numeric Errors

CVE-2014-9330

Severity Medium
Score 5/10

Summary

Integer overflow in tif_packbits.c in bmp2tif in libtiff up to v4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.

  • LOW
  • NETWORK
  • NONE
  • NONE
  • NONE
  • PARTIAL

CWE-189 - Numeric Errors

Weaknesses in this category are related to improper calculation or conversion of numbers.

Advisory Timeline

  • Published