Back

HIGH

LibTIFF: heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c

Published Jan 14, 2018

Description

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as low severity because it allows a remote attacker to cause a heap-based buffer over-read, it could lead to information leakage, it does not compromise system security or integrity.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 14, 2018
Updated Aug 5, 2024
Reserved Jan 12, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 12, 2018