Описание
libvips is a fast image processing library with low memory needs. The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
A flaw was found in libvips, an image processing library. The tiffload operation, which handles loading TIFF images, could incorrectly identify the number of channels in embedded JPEG or JPEG2000 tiles. This vulnerability may allow a local attacker with low privileges to trigger a buffer overflow, potentially leading to data corruption, system instability, or the disclosure of limited sensitive information.
Отчет
This flaw is rated as Important. A local attacker with low privileges could exploit a buffer overflow in libvips when processing a specially crafted TIFF image containing malformed JPEG or JPEG2000-encoded tiles. This could lead to application crashes, data corruption, or potentially arbitrary code execution, significantly impacting the integrity and availability of systems that handle untrusted image files.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
libvips is a fast image processing library with low memory needs. The ...
EPSS
7.3 High
CVSS3