Total vulnerabilities in the database
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.
Software | From | Fixed in |
---|---|---|
libtiff / libtiff | - | 4.4.0 |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |