Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18495

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the tiff2pdf utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit StripByteCounts value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

Отчет

This Moderate impact heap-buffer overflow in libtiff's tiff2pdf utility can lead to a denial of service or potential memory corruption when processing specially crafted BigTIFF files. The flaw arises from an integer truncation during strip length calculation, resulting in an undersized buffer. Exploitation requires local access and user interaction, such as opening a malicious file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 4cephUnder investigation
Red Hat Ceph Storage 6cephUnder investigation
Red Hat Ceph Storage 7cephUnder investigation
Red Hat Ceph Storage 8cephUnder investigation
Red Hat Ceph Storage 9cephUnder investigation
Red Hat Enterprise Linux 10boostUnder investigation
Red Hat Enterprise Linux 10cephUnder investigation
Red Hat Enterprise Linux 10libtiffUnder investigation
Red Hat Enterprise Linux 6libtiffUnder investigation
Red Hat Enterprise Linux 7compat-libtiff3Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2531414libtiff: libtiff: heap-buffer overflow via numeric truncation in the JPEG raw passthrough

EPSS

Процентиль: 2%
0.00117
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
10 дней назад

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

CVSS3: 6.1
nvd
10 дней назад

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

CVSS3: 6.1
debian
10 дней назад

A flaw was found in libtiff. A heap-buffer overflow vulnerability exis ...

suse-cvrf
4 дня назад

Security update for tiff

CVSS3: 6.1
github
10 дней назад

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

EPSS

Процентиль: 2%
0.00117
Низкий

6.1 Medium

CVSS3