Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7632
HistoryOct 23, 2018 - 3:21 a.m.

Buffer Overflow

2018-10-2303:21:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.283 Low

EPSS

Percentile

96.9%

libtiff.so is vulnerable to buffer overflow. When JBIG is enabled, the JBIGDecode function in tif_jbig.c ignores the buffer size when decoding JBIG objects with arbitrary size, which can lead to an out-of-bounds write.

CPENameOperatorVersion
libtiff.sole5.7.0
libtiffle4.0.6.2