libtiff
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*, +1 more
- <= 4.7.1
A NULL pointer dereference vulnerability has been identified in libtiff versions prior to 4.7.1. The issue arises in the tif_open.c component, where improper handling of TIFF directory tags can lead to a crash.
Exploitation of this vulnerability causes a segmentation fault, leading to a crash of the application.
The vulnerability can be reproduced using the tiffcrop tool included with libtiff. The command involves specifying a crafted TIFF file that triggers the NULL pointer dereference. This can be done by using the 'tiffcrop' command with the '-D' option to set the debug level, along with the path to the crafted TIFF file that exploits the vulnerability.
Users can upgrade to libtiff version 4.7.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.