CVE-2020-35524: Buffer Overflow
A flaw was found in libtiff 4.1.0. A heap-based buffer overflow exists in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution.
References:
https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22 https://gitlab.com/libtiff/libtiff/-/mergerequests/159
Other sources
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
— Launchpad
libtiff is vulnerable to a heap-based buffer overflow, caused by improper bounds checking in the handling of TIFF images in TIFF2PDF tool. By persuading a victim to open a specially-crafted TIFF file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35524.
What is the severity of CVE-2020-35524?
The severity of CVE-2020-35524 is medium.
What software is affected by CVE-2020-35524?
The software affected by CVE-2020-35524 is libtiff version up to 4.0.9-5ubuntu0.4, 4.1.0+, 4.0.3-7ubuntu0.11+, 4.0.6-1ubuntu0.8, 4.1.0+git191117-2~deb10u4, 4.1.0+git191117-2~deb10u8, 4.2.0-1+deb11u4, 4.5.0-6, and 4.5.1+git230720-1.
What is the remedy for CVE-2020-35524?
The remedy for CVE-2020-35524 depends on the software version: - For libtiff 4.0.9-5ubuntu0.4, the remedy is exactly version 4.0.9-5ubuntu0.4. - For libtiff 4.1.0+ and 4.1.0+git191117-2~deb10u4, the remedy is exactly version 4.1.0+. - For libtiff 4.0.3-7ubuntu0.11+, the remedy is exactly version 4.0.3-7ubuntu0.11+. - For libtiff 4.0.6-1ubuntu0.8, the remedy is exactly version 4.0.6-1ubuntu0.8. - For libtiff 4.2.0-1+deb11u4, the remedy is exactly version 4.2.0-1+deb11u4. - For libtiff 4.5.0-6 and 4.5.1+git230720-1, the remedy is exactly version 4.5.0-6 or higher.
What are the references for CVE-2020-35524?
The references for CVE-2020-35524 are: - https://bugzilla.redhat.com/show_bug.cgi?id=1932044 - https://gitlab.com/libtiff/libtiff/-/merge_requests/159 - https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22