PT-2020-5718 · Libtiff+9 · Libtiff+9

Published

2020-11-10

·

Updated

2024-06-15

·

CVE-2020-35524

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: libtiff (affected versions not specified)
Description: A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4241
ALT-PU-2021-1345
ALT-PU-2021-2853
AZL-6655
BDU:2021-01527
CESA-2021_4241
CVE-2020-35524
DLA-2694-1
DSA-4869-1
MGASA-2021-0098
OESA-2021-1112
OPENSUSE-SU-2022:0480-1
OPENSUSE-SU-2022_0480-1
OPENSUSE-SU-2024:13381-1
RHSA-2021:4241
RHSA-2021_4241
RLSA-2021:4241
SUSE-SU-2022:0480-1
SUSE-SU-2022:0496-1
SUSE-SU-2022:14888-1
SUSE-SU-2022_14888-1
USN-4755-1
USN-5841-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff