REDHAT-BUG-2297636: Medium severity tiff vulnerability
A flaw was found in the libtiff library. An out-of-memory issue in the TIFFReadEncodedStrip function can be triggered when processing a crafted tiff file, allowing attackers to perform memory allocation of arbitrary sizes, resulting in a denial of service.
Reference: https://gitlab.com/libtiff/libtiff/-/issues/620
Upstream patch: https://gitlab.com/libtiff/libtiff/-/mergerequests/553
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2297636?
The severity of REDHAT-BUG-2297636 is classified as a denial of service vulnerability.
How do I fix REDHAT-BUG-2297636?
To fix REDHAT-BUG-2297636, update the libtiff library to the latest patched version.
What impact does REDHAT-BUG-2297636 have on affected systems?
REDHAT-BUG-2297636 can lead to denial of service by causing the application to crash when processing a specially crafted TIFF file.
Which versions of libtiff are affected by REDHAT-BUG-2297636?
The specific affected versions of libtiff are not detailed, but the flaw exists in the library's handling of TIFF files.
Is REDHAT-BUG-2297636 related to any specific operating systems?
REDHAT-BUG-2297636 primarily affects systems that utilize the libtiff library on Red Hat environments.