Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tiff | Jul 30, 2024 | May 30, 2006 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | May 30, 2006 |
| Suse | — | Upgrade libtiff6Upgrade libtiff-devel-docsUpgrade libtiff-develUpgrade tiffUpgrade tiff-docs | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libtiff-tools | Nov 8, 2024 | May 30, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub