libtiff
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*, +1 more
- <= 4.7.1
A double free vulnerability has been identified in libtiff versions prior to 4.7.1, specifically within the tools/tiffcrop.c component. This vulnerability can lead to memory corruption and potential application crashes.
Exploitation of this vulnerability causes a double free memory error, which can lead to memory corruption and application crashes.
The vulnerability can be reproduced by using the tiffcrop tool with the -F horiz and -I both options, along with a crafted TIFF file that triggers the double free condition. The issue can be further explored by referencing the stack trace available in the original issue discussion.
Users can update to libtiff version 4.7.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.