CVE-2020-18768: Buffer Overflow
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow in TIFFmemcpy at tifunix.c when parsing TIFF files. By persuading a victim to open a specially crafted TIFF file, a remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
There exists one heap buffer overflow in TIFFmemcpy in tifunix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this heap buffer overflow in libtiff?
The vulnerability ID for this heap buffer overflow in libtiff is CVE-2020-18768.
What is the affected software?
The affected software is libtiff version 4.0.10.
What is the severity of CVE-2020-18768?
The severity of CVE-2020-18768 is medium with a CVSS score of 5.5.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by crafting a malicious tiff file that triggers a heap buffer overflow in libtiff.
Is there a fix available for this vulnerability?
Yes, a fix is available. It is recommended to update to a patched version of libtiff.