First published: Tue Feb 23 2021(Updated: )
A flaw was found in libtiff 4.1.0. A heap-based buffer overflow exists in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. References: <a href="https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22">https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22</a> <a href="https://gitlab.com/libtiff/libtiff/-/merge_requests/159">https://gitlab.com/libtiff/libtiff/-/merge_requests/159</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libtiff Libtiff | <4.2.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =33 | |
NetApp ONTAP Select Deploy administration utility | ||
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
redhat/libtiff | <4.2.0 | 4.2.0 |
debian/tiff | 4.2.0-1+deb11u5 4.5.0-6+deb12u1 4.5.1+git230720-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-35524.
The severity of CVE-2020-35524 is medium.
The software affected by CVE-2020-35524 is libtiff version up to 4.0.9-5ubuntu0.4, 4.1.0+, 4.0.3-7ubuntu0.11+, 4.0.6-1ubuntu0.8, 4.1.0+git191117-2~deb10u4, 4.1.0+git191117-2~deb10u8, 4.2.0-1+deb11u4, 4.5.0-6, and 4.5.1+git230720-1.
The remedy for CVE-2020-35524 depends on the software version: - For libtiff 4.0.9-5ubuntu0.4, the remedy is exactly version 4.0.9-5ubuntu0.4. - For libtiff 4.1.0+ and 4.1.0+git191117-2~deb10u4, the remedy is exactly version 4.1.0+. - For libtiff 4.0.3-7ubuntu0.11+, the remedy is exactly version 4.0.3-7ubuntu0.11+. - For libtiff 4.0.6-1ubuntu0.8, the remedy is exactly version 4.0.6-1ubuntu0.8. - For libtiff 4.2.0-1+deb11u4, the remedy is exactly version 4.2.0-1+deb11u4. - For libtiff 4.5.0-6 and 4.5.1+git230720-1, the remedy is exactly version 4.5.0-6 or higher.
The references for CVE-2020-35524 are: - https://bugzilla.redhat.com/show_bug.cgi?id=1932044 - https://gitlab.com/libtiff/libtiff/-/merge_requests/159 - https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22