NULL pointer dereference in LibTIFF - CVE-2024-13978

 

NULL pointer dereference in LibTIFF - CVE-2024-13978

Published: August 5, 2025


Vulnerability identifier: #VU113648
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-13978
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the t2p_read_tiff_init() function in tools/tiff2pdf.c. A remote attacker can pass a specially crafted image to the application and perform a denial of service (DoS) attack.


Affected software

LibTIFF
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Business Automation Insights
libtiff-debuginfo
libtiff-debugsource
libtiff-devel
libtiff-static
libtiff-tools
libtiff-help
libtiff
libtiff-doc
libtiff6-64bit-debuginfo
libtiff6-64bit
libtiff-devel-64bit
tiff-docs
libtiff-devel-docs
tiff
libtiff6
tiff-debugsource
libtiff6-debuginfo
tiff-debuginfo
libtiff6-32bit
libtiff-devel-32bit
libtiff6-32bit-debuginfo

How to mitigate CVE-2024-13978

Install update from vendor's website.

Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
libtiff-debuginfo - update to 4.3.0-40
libtiff-debugsource - update to 4.3.0-40
libtiff-devel - update to 4.3.0-40
libtiff-static - update to 4.3.0-40
libtiff-tools - update to 4.3.0-40
libtiff-help - update to 4.3.0-40
libtiff - update to 4.3.0-40
libtiff - update to 4.6.0-4
libtiff-devel - update to 4.6.0-4
libtiff-tools - update to 4.6.0-4
libtiff-doc - update to 4.6.0-4
libtiff - addressed in versions 4.6.0-6.fc41.1, 4.6.0-6.fc41.2, 4.7.0-7.fc42, 4.7.0-8.fc43, 4.7.0-8.fc44
libtiff-devel - update to 4.7.0-150600.3.18.1
libtiff6-64bit-debuginfo - update to 4.7.0-150600.3.18.1
libtiff6-64bit - update to 4.7.0-150600.3.18.1
libtiff-devel-64bit - update to 4.7.0-150600.3.18.1
tiff-docs - update to 4.7.0-150600.3.18.1
libtiff-devel-docs - update to 4.7.0-150600.3.18.1
tiff - update to 4.7.0-150600.3.18.1
libtiff6 - update to 4.7.0-150600.3.18.1
tiff-debugsource - update to 4.7.0-150600.3.18.1
libtiff6-debuginfo - update to 4.7.0-150600.3.18.1
tiff-debuginfo - update to 4.7.0-150600.3.18.1
libtiff6-32bit - update to 4.7.0-150600.3.18.1
libtiff-devel-32bit - update to 4.7.0-150600.3.18.1
libtiff6-32bit-debuginfo - update to 4.7.0-150600.3.18.1

External References

Related Security Bulletins