Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libtiffUpgrade libtiff-devel | Dec 1, 2016 | Jun 8, 2006 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jun 8, 2006 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jun 8, 2006 |
| Ubuntu | — | Upgrade libtiff-tools | Nov 8, 2024 | Jun 8, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub