Impact
A defect in the libtiff command‑line tool allows an attacker to craft a malicious input file and invoke the thumbnail.c main() component such that arbitrary machine code can be executed. This vulnerability arises from a buffer overflow and an integer overflow condition (CWE-120 and CWE-190). The flaw grants an attacker complete control over the execution environment of the program, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability appears in the libtiff library as identified by commit 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938. Any installation of libtiff that has not yet incorporated the fix from the subsequent commit 9ce4d089bcf25496663776d9e6336738112f09a3 is susceptible. The issue is independent of vendor or product version, meaning all builds derived from the vulnerable source may be affected unless explicitly updated.
Risk and Exploitability
The CVSS score is 8.4 and EPSS is less than 1%, yet the vulnerability’s ability to execute arbitrary code places it in the high‑severity category. Since it is not listed in CISA's KEV catalog, there is no official record of exploitation yet; however, the low exploitation probability does not diminish the potential risk, especially for systems processing untrusted TIFF images.
OpenCVE Enrichment