Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34687
HistoryMar 15, 2022 - 6:07 a.m.

NULL Pointer Dereference

2022-03-1506:07:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.002 Low

EPSS

Percentile

60.0%

libtiff.so is vulnerable to NULL pointer dereference. The vulnerability exists in createImageSection function in tiffcrop.c because it doesn’t check for return value of limitMalloc which allows an attacker to cause an application crash by sending a crafted tiff file.