{"id":"ALPINE-CVE-2014-8127","details":"LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.","modified":"2026-08-27T12:17:45.418828703Z","published":"2017-06-26T15:29:00.237Z","upstream":["CVE-2014-8127"],"references":[{"type":"ADVISORY","url":"https://security.alpinelinux.org/vuln/CVE-2014-8127"}],"affected":[{"package":{"name":"tiff","ecosystem":"Alpine:v3.2","purl":"pkg:apk/alpine/tiff?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.7-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2014-8127.json"}},{"package":{"name":"tiff","ecosystem":"Alpine:v3.3","purl":"pkg:apk/alpine/tiff?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.7-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2014-8127.json"}},{"package":{"name":"tiff","ecosystem":"Alpine:v3.4","purl":"pkg:apk/alpine/tiff?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.7-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2014-8127.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}