First published: Tue Sep 07 2021(Updated: )
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
simplesystems LibTiff | =4.0.10 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19131 has a severity rating of medium due to its potential to cause a denial of service.
To fix CVE-2020-19131, apply the latest patches provided by IBM for Cognos Analytics and update LibTiff to a version higher than 4.0.10.
CVE-2020-19131 affects LibTiff version 4.0.10, and IBM Cognos Analytics versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.3.
The vulnerability in CVE-2020-19131 is caused by a heap-based buffer overflow in the "invertImage()" function within the "tiffcrop" component.
Yes, CVE-2020-19131 can lead to remote denial of service attacks if a victim is tricked into opening a specially crafted TIFF image.