Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23794
HistoryApr 10, 2020 - 12:36 a.m.

Arbitrary Code Execution

2020-04-1000:36:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.006 Low

EPSS

Percentile

78.5%

libtiff is vulnerable to arbitrary code execution. The vulnerability exists as several integer overflow flaws, leading to heap-based buffer overflows, were found in various libtiff color space conversion tools. An attacker could create a specially-crafted TIFF file, which once opened by an unsuspecting user, would cause the conversion tool to crash or, potentially, execute arbitrary code with the privileges of the user running the tool.

References