libtiff: information leak
Package(s): | libtiff | CVE #(s): | CVE-2015-8870 | ||||||||||||||||||||
Created: | February 1, 2017 | Updated: | February 1, 2017 | ||||||||||||||||||||
Description: | From the CVE entry:
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file. | ||||||||||||||||||||||
Alerts: |
|