REDHAT-BUG-2218744: Buffer Overflow
libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size after rotateImage() in tiffcrop cause heap-buffer-overflow and SEGV.
https://gitlab.com/libtiff/libtiff/-/issues/520 https://gitlab.com/libtiff/libtiff/-/mergerequests/467
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2218744?
The severity of REDHAT-BUG-2218744 is classified as high due to the potential for heap buffer overflow leading to application crashes.
How do I fix REDHAT-BUG-2218744?
To fix REDHAT-BUG-2218744, upgrade to the latest version of libtiff where the vulnerability has been patched.
What software is affected by REDHAT-BUG-2218744?
The affected software for REDHAT-BUG-2218744 is libtiff version 4.5.0.
What is the nature of the vulnerability in REDHAT-BUG-2218744?
The nature of the vulnerability in REDHAT-BUG-2218744 is a buffer overflow caused by incorrect buffer size updates after the rotateImage() function.
Can REDHAT-BUG-2218744 lead to data breaches?
While REDHAT-BUG-2218744 primarily leads to application crashes, it can create opportunities for exploitation that may lead to data breaches if combined with other vulnerabilities.