REDHAT-BUG-2251311: Medium severity LibTIFF libtiff vulnerability
An out-of-memory problem was found in libtiff that could be triggered by passing a craft tiff file to TIFFOpen() API. In this flaw a remote attackers could cause deny-of-services via a craft input (with size smaller than 379 KB).
Reference: https://gitlab.com/libtiff/libtiff/-/issues/614
Fixed at: https://gitlab.com/libtiff/libtiff/-/mergerequests/545 https://gitlab.com/libtiff/libtiff/-/commit/d6bbe53a96b031ab8b53d20241825ddf9e8bf8f1 https://gitlab.com/libtiff/libtiff/-/commit/264a28eff71cf0038ba7b235238512fa594fa42f https://gitlab.com/libtiff/libtiff/-/commit/abb4476fd2be87fc8ded3078e019f22f84ee0e8c
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2251311?
The severity of REDHAT-BUG-2251311 is classified as a denial-of-service vulnerability.
How do I fix REDHAT-BUG-2251311?
To fix REDHAT-BUG-2251311, update libtiff to the latest version that addresses this vulnerability.
Who can exploit REDHAT-BUG-2251311?
Any remote attacker can exploit REDHAT-BUG-2251311 by providing a crafted TIFF file to the TIFFOpen() API.
What are the potential impacts of REDHAT-BUG-2251311?
The potential impacts of REDHAT-BUG-2251311 include service disruption due to the out-of-memory issue.
Which software is affected by REDHAT-BUG-2251311?
The affected software under REDHAT-BUG-2251311 is libtiff.