REDHAT-BUG-2240995: Buffer Overflow
An issue was found in the tiffcp utility distributed by the libtiff package. Processing a crafted TIFF file may cause a heap-based buffer overflow, resulting in an application crash.
Reference: https://gitlab.com/libtiff/libtiff/-/issues/606
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2240995?
REDHAT-BUG-2240995 is classified as a critical vulnerability due to the potential for a heap-based buffer overflow.
How do I fix REDHAT-BUG-2240995?
To fix REDHAT-BUG-2240995, update the libtiff package to the latest version provided by your vendor.
What are the risks associated with REDHAT-BUG-2240995?
The risks of REDHAT-BUG-2240995 include application crashes and potential exploitation leading to unauthorized access.
Which software is affected by REDHAT-BUG-2240995?
REDHAT-BUG-2240995 affects the tiffcp utility within the libtiff package.
Is there a workaround for REDHAT-BUG-2240995?
A temporary workaround for REDHAT-BUG-2240995 involves avoiding the processing of untrusted TIFF files until a patch is applied.