Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10741
HistoryJan 15, 2019 - 8:51 a.m.

Remote Code Execution (RCE)

2019-01-1508:51:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.004 Low

EPSS

Percentile

74.9%

libtiff is vulnerable to remote code execution (RCE) attacks. The vulnerability exists in the t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.

References