#VU103977 Integer overflow in LibTIFF - CVE-2015-8870
Published: February 14, 2025
LibTIFF
LibTIFF
Description
The vulnerability allows a remote attacker to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory.
The vulnerability exists in tools/bmp2tiff.c in LibTIFF. A remote attacker can pass specially crafted width and length values in RLE4 or RLE8 data in a BMP file to the application, trigger integer overflow and cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory