Heap-based Buffer Overflow Vulnerability in LibTIFF 4.0.9
CVE-2018-16335
8.8HIGH
What is CVE-2018-16335?
The LibTIFF 4.0.9 version contains a vulnerability in the newoffsets handling within the ChopUpSingleUncompressedStrip function inside tif_dirread.c. This flaw allows remote attackers to exploit crafted TIFF files leading to a denial of service through a heap-based buffer overflow. When malicious files are processed, it can result in application crashes and may lead to further unspecified impacts, highlighting the importance of securing TIFF file handling in applications utilizing this library.