#VU20390 Integer overflow in LibTIFF - CVE-2019-14973
Published: August 26, 2019 / Updated: May 21, 2022
LibTIFF
LibTIFF
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks.
The vulnerability exists due to integer overflow in the "_TIFFCheckMalloc" and "_TIFFCheckRealloc" functions in the "tif_aux.c" file. A remote attacker can trick a victim to open a specially crafted file that contains crafted TIFF images, trigger integer overflow and crash the target application.