In LibTIFF 4.0.7, the program processes BMP images...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 8, 2025
Description
Published by the National Vulnerability Database
May 21, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jan 8, 2025
In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.
References