Buffer Overflow Vulnerability in LibTIFF Affects Bitmap Processing
CVE-2018-15209

8.8HIGH

Key Information:

Vendor

Libtiff

Status
Vendor
CVE Published:
8 August 2018

What is CVE-2018-15209?

The vulnerability in the ChopUpSingleUncompressedStrip function within the tif_dirread.c file of LibTIFF 4.0.9 may allow remote attackers to exploit a crafted TIFF file to induce a heap-based buffer overflow. This can lead to application crashes or potential further impacts that remain unspecified. Users should take immediate precautionary measures to ensure their systems are secure from exploitation via manipulated TIFF files.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.