First published: Tue Feb 23 2021(Updated: )
A flaw was found in libtiff 4.1.0 and before. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. References: <a href="https://gitlab.com/libtiff/libtiff/-/merge_requests/165">https://gitlab.com/libtiff/libtiff/-/merge_requests/165</a> <a href="https://gitlab.com/libtiff/libtiff/-/commit/b5a935d96b21cda0f434230cdf8ca958cd8b4eef">https://gitlab.com/libtiff/libtiff/-/commit/b5a935d96b21cda0f434230cdf8ca958cd8b4eef</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtiff | <4.2.0 | 4.2.0 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
TIFF | <4.2.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Fedora | =33 | |
NetApp ONTAP Select Deploy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35521 is classified as a denial of service vulnerability due to a memory allocation failure.
To mitigate CVE-2020-35521, upgrade libtiff to version 4.2.0 or apply the relevant patches for affected software.
CVE-2020-35521 affects libtiff versions 4.1.0 and prior, as well as specific versions of IBM Cognos Analytics.
Yes, CVE-2020-35521 can be exploited through a crafted TIFF file leading to a denial of service.
There are no specific publicly known exploits for CVE-2020-35521 as of yet, but the vulnerability poses a risk of service interruption.