---
title: "CVE-2015-7313\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-7313?format=md
keywords: index, follow
---

# CVE-2015-7313

Publication date 17 March 2017

Last updated 15 September 2025

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2015-7313?format=md#impact-score)

Toggle side navigation

## Description

LibTIFF before 4.0.7 allows remote attackers to cause a denial of service
(memory consumption and crash) via a crafted tiff file.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2015-7313?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tiff | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored end of standard support |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.04 LTS trusty | Ignored end of standard support |
| 12.04 LTS precise | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

as of 2021-02-24, no upstream fix

---

### [sbeattie](https://launchpad.net/~sbeattie)

likely fixed in upstream 4.0.7 release
reproducer in oss-security post

---

### [ccdm94](https://launchpad.net/~ccdm94)

bionic and later are not-affected and the issue
is not reproducible in trusty (no huge reallocs
are made, as would be expected), and is also
not reproducible in xenial (no reallocs made
at all, according to ltrace output) with the
POC file provided in the oss-security post.
No upstream patch was identified after analysis
of the libtiff changelog file, as well as the
change history for the tiffdither code. Since
this is a 2015 issue, trusty and xenial will
be marked as ignored.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7313)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-7313)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-7313)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-7313)

### Other references

* <https://marc.info/?l=oss-security&m=144284777006804&w=2>
* <https://www.cve.org/CVERecord?id=CVE-2015-7313>
