A NULL pointer dereference flaw was found in Libtiffs LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libtiff | Libtiff | * | 4.5.0 (excluding) |
Red Hat Enterprise Linux 9 | RedHat | libtiff-0:4.4.0-10.el9 | * |
Tiff | Ubuntu | kinetic | * |
Tiff | Ubuntu | lunar | * |
Tiff | Ubuntu | trusty | * |
Tiff | Ubuntu | upstream | * |
Tiff | Ubuntu | xenial | * |