Libtiff

Libtiff

262 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.59%
  • Veröffentlicht 18.01.2017 17:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.

Exploit
  • EPSS 0.93%
  • Veröffentlicht 12.01.2017 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.

Exploit
  • EPSS 6.4%
  • Veröffentlicht 06.01.2017 21:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code execution. Vulnerability can be triggered via a save...

  • EPSS 0.74%
  • Veröffentlicht 06.12.2016 18:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4...

  • EPSS 0.42%
  • Veröffentlicht 22.11.2016 19:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."

  • EPSS 0.42%
  • Veröffentlicht 22.11.2016 19:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.

  • EPSS 0.42%
  • Veröffentlicht 22.11.2016 19:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35100.

  • EPSS 0.42%
  • Veröffentlicht 22.11.2016 19:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.

  • EPSS 0.42%
  • Veröffentlicht 22.11.2016 19:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 35098, aka "t2p_process_jpeg_strip heap-buffer-overflow."

Medienbericht
  • EPSS 0.6%
  • Veröffentlicht 22.11.2016 19:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Pre...