Heap-based Buffer Overflow Vulnerability in LibTIFF 4.0.9
CVE-2018-16335

8.8HIGH

Key Information:

Vendor

Libtiff

Status
Vendor
CVE Published:
2 September 2018

What is CVE-2018-16335?

The LibTIFF 4.0.9 version contains a vulnerability in the newoffsets handling within the ChopUpSingleUncompressedStrip function inside tif_dirread.c. This flaw allows remote attackers to exploit crafted TIFF files leading to a denial of service through a heap-based buffer overflow. When malicious files are processed, it can result in application crashes and may lead to further unspecified impacts, highlighting the importance of securing TIFF file handling in applications utilizing this library.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.