First published: Thu Jun 15 2023(Updated: )
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. <a href="https://gitlab.com/libtiff/libtiff/-/merge_requests/472">https://gitlab.com/libtiff/libtiff/-/merge_requests/472</a>
Affected Software | Affected Version | How to fix |
---|---|---|
TIFF | <4.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2215206 is considered a high severity vulnerability due to its potential for exploit via crafted TIFF images.
To fix REDHAT-BUG-2215206, upgrade to LibTIFF version 4.5.0 or later.
REDHAT-BUG-2215206 affects LibTIFF versions prior to 4.5.0.
REDHAT-BUG-2215206 is a heap-based use after free vulnerability.
Yes, REDHAT-BUG-2215206 can potentially be exploited remotely through crafted TIFF images.