tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 20, 2024
Description
Published by the National Vulnerability Database
Oct 14, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Dec 20, 2024
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.
References