A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
CVE-2024-7006 - High Severity Vulnerability
Vulnerable Libraries - openjpeg5875a6b44618fb7dfd5cd6d742533eaee2014060, openjpeg5875a6b44618fb7dfd5cd6d742533eaee2014060
Vulnerability Details
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
Publish Date: 2024-08-08
URL: CVE-2024-7006
CVSS 3 Score Details (7.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://gitlab.com/libtiff/libtiff/-/merge_requests/559
Release Date: 2024-08-08
Fix Resolution: 818fb8ce881cf839fbc710f6690aadb992aa0f9e
Step up your Open Source Security Game with Mend here