Описание
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
A heap-based buffer overflow vulnerability was found in LibTIFF's tiffcrop utility in the extractContigSamplesBytes() function. This flaw allows an attacker to pass a crafted TIFF image file to the tiffcrop utility, which causes an out-of-bounds read access resulting in an application crash, eventually leading to a denial of service.
Отчет
This vulnerability in tiffcrop is classified as moderate severity rather than important because, while it leads to a denial of service (DoS) via a crash, the impact is not critical in terms of system compromise or data loss. The vulnerability, caused by a heap-based buffer overflow, results in an out-of-bounds read, which disrupts the functionality of the tiffcrop utility but does not allow an attacker to execute arbitrary code or escalate privileges. Additionally, exploitation requires the attacker to provide a specially crafted TIFF file, meaning it is not easily triggered remotely without user interaction. While it poses a disruption to operations, it does not lead to broader system vulnerabilities or compromise, justifying its classification as moderate severity.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libtiff | Not affected | ||
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Not affected | ||
| Red Hat Enterprise Linux 7 | libtiff | Not affected | ||
| Red Hat Enterprise Linux 8 | compat-libtiff3 | Not affected | ||
| Red Hat Enterprise Linux 8 | libtiff | Will not fix | ||
| Red Hat Enterprise Linux 9 | libtiff | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSample ...
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
EPSS
5.5 Medium
CVSS3