Aller au contenu

Fiche vulnérabilité

CVE-2024-7006 : faille élevée libtiff libtiff (CVSS 7.5)

Description

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
12 août 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • libtiff libtiff
  • redhat enterprise linux
  • redhat enterprise linux for arm 64
  • redhat enterprise linux for power little endian eus
  • redhat enterprise linux server aus

Références

Rechercher une autre vulnérabilité dans la base CVE