Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4775

Опубликовано: 24 мар. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.7.1-2package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2450768

  • https://gitlab.com/libtiff/libtiff/-/work_items/807

  • https://gitlab.com/libtiff/libtiff/-/work_items/787

  • https://gitlab.com/libtiff/libtiff/-/commit/782a11d6b5b61c6dc21e714950a4af5bf89f023c

EPSS

Процентиль: 43%
0.00553
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

CVSS3: 7.8
redhat
4 месяца назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

CVSS3: 7.8
nvd
4 месяца назад

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

CVSS3: 7.8
msrc
4 месяца назад

Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing

suse-cvrf
2 месяца назад

Security update for tiff

EPSS

Процентиль: 43%
0.00553
Низкий