CVE-2020-35523: Integer Overflow
An integer overflow flaw was found in libtiff that exists in the tifgetimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
In libtiff 4.1.0, an integer overflow vulnerability exists in tifgetimage.c file. By enticing a user to open a craft TIFF file, an attacker may leverage the vulnerability to inject and execute arbitrary code.
References:
https://gitlab.com/libtiff/libtiff/-/commit/c8d613ef497058fe653c467fc84c70a62a4a71b2 https://gitlab.com/libtiff/libtiff/-/mergerequests/160
— Red Hat
libtiff could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the tifgetimage.c file. By persuading a victim to open a specially-crafted TIFF file, an attacker could overflow a buffer and execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35523?
CVE-2020-35523 is an integer overflow flaw in libtiff that allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file.
What is the severity of CVE-2020-35523?
The severity of CVE-2020-35523 is high with a CVSS score of 7.8.
Which software is affected by CVE-2020-35523?
The software affected by CVE-2020-35523 includes versions 4.0.3-7ubuntu0.11+, 4.0.6-1ubuntu0.8, 4.0.9-5ubuntu0.4, 4.1.0+, 4.1.0+git191117-2~deb10u4, 4.1.0+git191117-2~deb10u8, 4.2.0-1+deb11u4, 4.5.0-6, 4.5.1+git230720-1, 4.2.0, and 4.0.9-20.el8.
How can I fix CVE-2020-35523?
To fix CVE-2020-35523, update the libtiff software to version 4.1.0 or higher.
Where can I find more information about CVE-2020-35523?
More information about CVE-2020-35523 can be found at the following references: [link1](https://bugzilla.redhat.com/show_bug.cgi?id=1932040), [link2](https://gitlab.com/libtiff/libtiff/-/commit/c8d613ef497058fe653c467fc84c70a62a4a71b2), [link3](https://gitlab.com/libtiff/libtiff/-/merge_requests/160).