REDHAT-BUG-2251326: Medium severity LibTIFF libtiff vulnerability
An out-of-memory problem was found in libtiff that could be triggered by passing a craft tiff file to TIFFRasterScanlineSize64() API. In this flaw a remote attackers could cause deny-of-services via a craft input (with size smaller than 379 KB).
Reference: https://gitlab.com/libtiff/libtiff/-/issues/621
Fixed at: https://gitlab.com/libtiff/libtiff/-/mergerequests/553 https://gitlab.com/libtiff/libtiff/-/commit/6791bff9f76c2a7f2f18c80b95c796e93fae6a34
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2251326?
The severity of REDHAT-BUG-2251326 is classified as medium due to the potential for denial-of-service attacks.
How do I fix REDHAT-BUG-2251326?
To fix REDHAT-BUG-2251326, update the libtiff library to the latest version that addresses this vulnerability.
What type of attack is associated with REDHAT-BUG-2251326?
REDHAT-BUG-2251326 is associated with a denial-of-service attack that can be triggered by malicious TIFF files.
Which software is affected by REDHAT-BUG-2251326?
The software affected by REDHAT-BUG-2251326 is the libtiff library.
Can REDHAT-BUG-2251326 be exploited remotely?
Yes, REDHAT-BUG-2251326 can be exploited remotely by sending a specially crafted TIFF file.