Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-29694
HistoryFeb 15, 2023 - 12:00 a.m.

LibTIFF tiffcrop.c:3724 buffer overflow vulnerability

2023-02-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
libtiff
buffer overflow
tiffcrop
denial of service
boundary error
crafted tiff file

EPSS

0.001

Percentile

31.6%

LibTIFF is a library for reading and writing TIFF (Tagged Image File Format) files. The library contains a number of command line tools for working with TIFF files. LibTIFF suffers from a buffer overflow vulnerability, which stems from a boundary error in tiffcrop at tools/tiffcrop.c:3724 when handling untrusted input. An attacker could exploit this vulnerability to cause a denial of service via a crafted tiff file.