Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17537
HistoryMay 02, 2019 - 5:45 a.m.

Denial Of Service (DoS)

2019-05-0205:45:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.005 Low

EPSS

Percentile

76.8%

libtiff is vulnerable to heap-based buffer overflow vulnerability. Remote attackers can cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image with zero tiles. loadImage() function in tiffcrop.c. loadImage() will read the numbers of tiles by calling TIFFNumberOfTiles() which creates a potential attack vector via crafted tiff tiles, which may result in DoS or code execution.