Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-72102
HistoryAug 31, 2022 - 12:00 a.m.

LibTIFF Buffer Overflow Vulnerability (CNVD-2022-72102)

2022-08-3100:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
libtiff
buffer overflow
vulnerability
extractimagesection
denial of service
crafted tiff file

0.001 Low

EPSS

Percentile

31.7%

LibTIFF is a library for reading and writing TIFF (Tagged Image File Format) files. The library contains a number of command-line tools for processing TIFF files. libTIFF suffers from a security vulnerability that stems from the lack of proper validation of user-supplied data by extractImageSection in its tools/tiffcrop.c:6905, where specially crafted data could trigger a read beyond the end of the allocated buffer. An attacker could exploit this vulnerability to cause a denial of service via a crafted tiff file.

CPENameOperatorVersion
libtiff libtiffle4.4.0