Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7496
HistorySep 17, 2018 - 9:29 a.m.

Denial Of Service (DoS)

2018-09-1709:29:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.008 Low

EPSS

Percentile

81.2%

libtiff.so is vulnerable to denial of service (DoS). The attacker can trigger the attacker by sending a malicious TIFF image to the cpTags in tools/tiff2bw.c and tools/pal2rgb.c, causing two out-of-bounds writes that can crash the application or cause arbitrary code to be executed.

CPENameOperatorVersion
libtiff.sole5.2.0