Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41175
HistoryJul 10, 2023 - 11:18 a.m.

Buffer Overflow

2023-07-1011:18:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
buffer overflow
libtiff
uv_encode
tiff file
little-endian
big-endian
application crash

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

10.5%

libtiff.so is vulnerable to Buffer Overflows. The vulnerability exists in uv_encode function at tif_luv.c when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian resulting in an application crash.

CPENameOperatorVersion
libtiff.sole6.0.0
libtiff.sole6.0.0

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

10.5%