CVE-2020-19144: Buffer Overflow
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in TIFFmemcpy' funtion in the component 'tifunix.c'.
Other sources
libtiff is vulnerable to a denial of service, caused by a heap-based buffer overflow in TIFFmemcpy function in the component tifunix.c. By persuading a victim to open a specially-crafted TIFF file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-19144?
CVE-2020-19144 has a high severity rating as it can lead to a denial of service due to a buffer overflow.
How do I fix CVE-2020-19144?
To fix CVE-2020-19144, you should apply the recommended patches provided by the vendor for the affected versions of the software.
Which versions of LibTiff are affected by CVE-2020-19144?
CVE-2020-19144 affects LibTiff version 4.0.10.
What impact does CVE-2020-19144 have on my system?
CVE-2020-19144 can cause a denial of service, impacting the availability of applications using the affected libraries.
Is there a workaround for CVE-2020-19144?
There are no specific workarounds documented for CVE-2020-19144, so applying the patch is recommended.