Back

MEDIUM

libtiff: divide by zero in the tiffdither tool

Published Mar 12, 2018

Description

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 12, 2018
Updated Aug 6, 2024
Reserved Oct 10, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 7, 2014