[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2300 --- libtiff

ID: oval:org.secpod.oval:def:1701859Date: (C)2023-11-24   (M)2024-03-14
Class: PATCHFamily: unix




There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file. A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file

Platform:
Amazon Linux 2
Product:
libtiff
Reference:
ALAS2-2023-2300
CVE-2020-18768
CVE-2022-0891
CVE-2023-3164
CVE    3
CVE-2022-0891
CVE-2023-3164
CVE-2020-18768
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:libtiff:libtiff

© SecPod Technologies