Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-15760
HistoryFeb 15, 2023 - 12:00 a.m.

LibTIFF out-of-bounds read vulnerability

2023-02-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
libtiff library
tiff file
out-of-bounds
vulnerability
denial of service
crafted file
untrusted input

EPSS

0.001

Percentile

30.3%

LibTIFF is a library for reading and writing TIFF (Tagged Image File Format) files. The library contains a number of command-line tools for processing TIFF files. libTIFF suffers from an out-of-bounds read vulnerability, which stems from a boundary error in iffcrop at tools/tiffcrop.c:3488 when handling untrusted input. An attacker could exploit this vulnerability to cause a denial of service via a crafted tiff file.