Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37669
HistoryOct 24, 2022 - 3:59 a.m.

Denial Of Service (DoS)

2022-10-2403:59:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
dos
libdiff.so
tiffcrop.c
heap buffer overflow
tiff image
application crash
memory access

EPSS

0.001

Percentile

36.1%

libdiff.so is vulnerable to denial of service. The vulnerability is due to the multiple heap buffer overflows in tiffcrop.c, allowing an attacker to trigger unsafe or out-of-bounds memory access via maliciously crafted TIFF image, resulting in an application crash.