Executive brief
LibTIFF is a widely used library for reading and writing Tag Image File Format (TIFF) files. A vulnerability in this library allows a remote attacker to crash applications that process image files by providing a specially crafted BMP file. This could lead to a denial-of-service condition, impacting the availability of services or software that rely on LibTIFF for image processing.
Technical details
A heap-based buffer overflow exists in the PackBitsEncode function within tif_packbits.c in LibTIFF 4.0.6 and earlier. The vulnerability is triggered when the library processes a maliciously crafted BMP file via the bmp2tiff tool or other interfaces calling TIFFWriteScanline. The root cause is a failure to properly check the length of the buffer (bp) passed to the encoder. An attacker can exploit this by enticing a user to open a crafted image, resulting in an out-of-bounds read/write that causes a segmentation fault and application crash. The issue was addressed in LibTIFF version 4.0.7.
Affected products
- LibTIFF libtiff 4.0.6 and earlier
Timeline
- 2016-04-27: disclosed: Vulnerability details shared on oss-security mailing list.
- 2017-01-09: patched: Gentoo GLSA indicates fix available in version 4.0.7.
- 2017-01-20: advisory: NVD publication date.