ZeroHour

CVE-2020-35524

CVSS 3.1
7.8 high
EPSS
2%p78
Published
()
Modified
Description

A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Vendors
libtiffdebianfedoraprojectnetappredhat
Products
libtiff, debian linux, fedora, ontap select deploy administration utility, enterprise linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.