LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jan 14, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libtiffUpgrade libtiff-devel | Sep 12, 2019 | Jan 14, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libtiff-develUpgrade libtiff | Sep 25, 2019 | Jan 14, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 14, 2018 |
| Ubuntu | — | Upgrade tiff | Nov 19, 2024 | Jan 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub