Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libtiffUpgrade libtiff-devel | Dec 1, 2016 | May 3, 2011 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | May 3, 2011 |
| Oracle_linux | — | Upgrade libtiff-develUpgrade libtiff | Oct 16, 2024 | May 3, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 22, 2010 |
| Suse | — | Upgrade tiff-docsUpgrade libtiff3Upgrade libtiff5-32bitUpgrade libtiff-develUpgrade libtiff3-x86Upgrade libtiff3-32bitUpgrade libtiff6Upgrade tiffUpgrade libtiff-devel-docsUpgrade libtiff-devel-32bitUpgrade libtiff5 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libtiff4 | Nov 8, 2024 | May 3, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub