Описание
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the tiff2pdf utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit StripByteCounts value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Отчет
This Moderate impact heap-buffer overflow in libtiff's tiff2pdf utility can lead to a denial of service or potential memory corruption when processing specially crafted BigTIFF files. The flaw arises from an integer truncation during strip length calculation, resulting in an undersized buffer. Exploitation requires local access and user interaction, such as opening a malicious file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 4 | ceph | Under investigation | ||
| Red Hat Ceph Storage 6 | ceph | Under investigation | ||
| Red Hat Ceph Storage 7 | ceph | Under investigation | ||
| Red Hat Ceph Storage 8 | ceph | Under investigation | ||
| Red Hat Ceph Storage 9 | ceph | Under investigation | ||
| Red Hat Enterprise Linux 10 | boost | Under investigation | ||
| Red Hat Enterprise Linux 10 | ceph | Under investigation | ||
| Red Hat Enterprise Linux 10 | libtiff | Under investigation | ||
| Red Hat Enterprise Linux 6 | libtiff | Under investigation | ||
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
A flaw was found in libtiff. A heap-buffer overflow vulnerability exis ...
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
EPSS
6.1 Medium
CVSS3