First published: Wed Sep 27 2023(Updated: )
An issue was found in the tiffcp utility distributed by the libtiff package. Processing a crafted TIFF file may cause a heap-based buffer overflow, resulting in an application crash. Reference: <a href="https://gitlab.com/libtiff/libtiff/-/issues/606">https://gitlab.com/libtiff/libtiff/-/issues/606</a>
Affected Software | Affected Version | How to fix |
---|---|---|
libtiff |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2240995 is classified as a critical vulnerability due to the potential for a heap-based buffer overflow.
To fix REDHAT-BUG-2240995, update the libtiff package to the latest version provided by your vendor.
The risks of REDHAT-BUG-2240995 include application crashes and potential exploitation leading to unauthorized access.
REDHAT-BUG-2240995 affects the tiffcp utility within the libtiff package.
A temporary workaround for REDHAT-BUG-2240995 involves avoiding the processing of untrusted TIFF files until a patch is applied.