Wind River Support Network

HomeDefectsLIN1021-6330
Fixed

LIN1021-6330 : Security Advisory - tiff - CVE-2020-18768

Created: Aug 22, 2023    Updated: Aug 29, 2023
Resolved Date: Aug 29, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.

CREATE(Triage):(User=admin) CVE-2020-18768 (https://nvd.nist.gov/vuln/detail/CVE-2020-18768)
Live chat
Online