PT-2020-5716 · None+8 · Libtiff+8

Published

2020-11-15

·

Updated

2024-06-15

·

CVE-2020-35522

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: LibTIFF (affected versions not specified)
Description: The issue is related to a memory buffer overflow in the TIFF to RGBA conversion module of LibTIFF, which can be exploited by a remote attacker using a specially crafted TIFF file. This can lead to a denial of service attack, resulting in an abort. A memory malloc failure in tif pixarlog.c is also associated with this issue, allowing an attacker to cause a remote denial of service with a crafted TIFF document.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4241
ALT-PU-2021-1345
ALT-PU-2021-2853
AZL-6653
BDU:2021-01525
CESA-2021_4241
CVE-2020-35522
MGASA-2021-0098
OESA-2021-1112
OPENSUSE-SU-2022:0480-1
OPENSUSE-SU-2022_0480-1
OPENSUSE-SU-2024:13381-1
RHSA-2021:4241
RHSA-2021_4241
RLSA-2021:4241
SUSE-SU-2022:0480-1
SUSE-SU-2022:0496-1
SUSE-SU-2022:14888-1
SUSE-SU-2022_14888-1
USN-5421-1

Affected Products

Alt Linux
Almalinux
Centos
Libtiff
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu