Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4775

Опубликовано: 24 мар. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.7.1-2package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2450768

  • https://gitlab.com/libtiff/libtiff/-/work_items/807

  • https://gitlab.com/libtiff/libtiff/-/work_items/787

  • https://gitlab.com/libtiff/libtiff/-/commit/782a11d6b5b61c6dc21e714950a4af5bf89f023c

EPSS

Процентиль: 24%
0.00081
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
15 дней назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

CVSS3: 7.8
redhat
15 дней назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

CVSS3: 7.8
nvd
15 дней назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

msrc
13 дней назад

Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing

CVSS3: 7.8
github
15 дней назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

EPSS

Процентиль: 24%
0.00081
Низкий