LibTIFF.ExtractImageSection.Heap.Buffer.Overflow

description-logoDescription

This indicates an attack attempt to exploit a Buffer Overflow Vulnerability in LibTIFF.
The vulnerability is due to lack of validation of user-supplied inputs. A remote attacker may exploit this vulnerability by enticing the victim to open a maliciously crafted .tiff file. Successful exploitation could lead to code execution under the security context of the user.

affected-products-logoAffected Products

LibTIFF prior to and including 4.3.0

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://gitlab.com/freedesktop-sdk/mirrors/gitlab/libtiff/libtiff/-/commit/232282fd8f9c21eefe8d2d2b96cdbbb172fe7b7c

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-07-24 25.607 Default_action:pass:drop
2023-07-11 24.598