CVE-2024-7006
12.08.2024, 13:38
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.Enginsight
Vendor | Product | Version |
---|---|---|
libtiff | libtiff | 3.5.1 ≤ 𝑥 ≤ 4.6.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
redhat | enterprise_linux_for_arm_64 | 9.2 |
redhat | enterprise_linux_for_power_little_endian_eus | 9.2 |
redhat | enterprise_linux_server_aus | 9.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gdal |
| ||||||||||||||||
neuron |
| ||||||||||||||||
qtwebengine-opensource-src |
| ||||||||||||||||
texmaker |
| ||||||||||||||||
tiff |
|
Common Weakness Enumeration
References