CVE-2019-17546
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 14, 2019
Updated: Dec 20, 2024
CWE ID 787
CWE ID 190
Summary
CVE-2019-17546 is a vulnerability affecting LibTIFF version 4.0.10 and above, as used in GDAL up to 3.0.1 and other products. This issue involves an integer overflow in the function tif_getimage.c, leading to a heap-based buffer overflow. A specially crafted RGBA image can trigger this vulnerability under certain conditions, resulting in potential code execution or denial of service.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibTIFF
Affected Vendors
- Libtiff
- OSGeo