CVE-2020-19143: Buffer Overflow
Published Sep 9, 2021
·Updated
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tifdir.c'.
Affected Software
3 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
Simplesystems Libtiff=4.0.10
Debian Debian Linux=11.0
Remediation
Patch Available
Patch Available
Event History
Sep 9, 2021
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19143?
CVE-2020-19143 is classified with a medium severity due to its potential to cause a denial of service.
2
How do I fix CVE-2020-19143?
To fix CVE-2020-19143, upgrade to a patched version of LibTiff, such as 4.1.0+git191117-2~deb10u4 or later.
3
Which versions of LibTiff are affected by CVE-2020-19143?
LibTiff version 4.0.10 is directly affected by CVE-2020-19143.
4
Can CVE-2020-19143 lead to data loss?
CVE-2020-19143 primarily leads to a denial of service rather than directly causing data loss.
5
Is CVE-2020-19143 easy to exploit?
Exploitation of CVE-2020-19143 may require specific conditions in the input TIFF files, making it a target for deliberate attacks.