CVE-2024-7006
12.08.2024, 13:38
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libtiff | libtiff | 3.5.1 ≤ 𝑥 ≤ 4.6.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux_for_arm_64 | 9.2 |
| redhat | enterprise_linux_for_power_little_endian_eus | 9.2 |
| redhat | enterprise_linux_server_aus | 9.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tiff |
| ||||||||||||||||||
| qtwebengine-opensource-src |
| ||||||||||||||||||
| texmaker |
| ||||||||||||||||||
| gdal |
| ||||||||||||||||||
| neuron |
|
Common Weakness Enumeration
References