Back

HIGH

libtiff: Two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c

Published Sep 16, 2018

Description

An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as low severity because it could lead to a denial of service through an out-of-bounds write, it may crash the application, it does not pose a significant risk to system security or integrity.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 16, 2018
Updated Aug 5, 2024
Reserved Sep 16, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 16, 2018