Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-72096
HistoryOct 25, 2022 - 12:00 a.m.

LibTIFF Buffer Overflow Vulnerability (CNVD-2022-72096)

2022-10-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
41
libtiff
buffer overflow
vulnerability
tiff files
command-line tools
version 4.4.0
heap buffer overflow
attacker
memory access
image file
application crash
information disclosure
security impact

EPSS

0.001

Percentile

36.1%

LibTIFF is a library for reading and writing TIFF (Tagged Image File Format) files. The library contains a number of command-line tools for handling TIFF files.LibTIFF version 4.4.0 is vulnerable to a buffer overflow vulnerability, which stems from the existence of multiple heap buffer overflows that could be exploited by an attacker to trigger an insecure or out-of-bounds memory access via a crafted TIFF image file, resulting in an application crash, potential information disclosure, or any other context-sensitive impact.