CVE-2020-19131: Buffer Overflow
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
Other sources
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow in the invertImage() function. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-19131?
CVE-2020-19131 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2020-19131?
To fix CVE-2020-19131, apply the latest patches provided by IBM for Cognos Analytics and update LibTiff to a version higher than 4.0.10.
What types of software are affected by CVE-2020-19131?
CVE-2020-19131 affects LibTiff version 4.0.10, and IBM Cognos Analytics versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.3.
What component is responsible for the vulnerability in CVE-2020-19131?
The vulnerability in CVE-2020-19131 is caused by a heap-based buffer overflow in the "invertImage()" function within the "tiffcrop" component.
Can CVE-2020-19131 lead to remote attacks?
Yes, CVE-2020-19131 can lead to remote denial of service attacks if a victim is tricked into opening a specially crafted TIFF image.