PT-2026-28086 · Libtiff+1 · Libtiff+1

CVE-2026-33809

·

Publicado

2026-03-25

·

Atualizado

2026-07-30

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LibTIFF (affected versions not specified)
Description A specially designed TIFF file can trigger an out-of-memory error or excessive resource usage during image decoding. The issue arises from the image decoding process attempting to allocate up to 4GiB of memory when processing a malicious IFD offset within the TIFF file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-07249
CVE-2026-33809
GHSA-44P7-9XX4-HF2G
GO-2026-4815
OPENSUSE-SU-2026:10628-1
OPENSUSE-SU-2026:10856-1
OPENSUSE-SU-2026:11290-1
OPENSUSE-SU-2026:20963-1
OPENSUSE-SU-2026:21436-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:7291
RHSA-2026:7385
SUSE-SU-2026:1135-1

Produtos afetados

Libtiff
Red Os