A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
{ "vanir_signatures": [ { "id": "CVE-2020-35524-4f566ef4", "signature_type": "Function", "target": { "file": "tools/tiff2pdf.c", "function": "t2p_read_tiff_size" }, "deprecated": false, "digest": { "length": 3961.0, "function_hash": "162918101681779814229328512498276279333" }, "signature_version": "v1", "source": "https://gitlab.com/rzkn/libtiff@7be2e452ddcf6d7abca88f41d3761e6edab72b22" }, { "id": "CVE-2020-35524-784ef608", "signature_type": "Line", "target": { "file": "tools/tiff2pdf.c" }, "deprecated": false, "digest": { "line_hashes": [ "63000372611281549800537825189411368918", "169840123599508707064489978991016675369", "207475852092280604137846944425818913699", "23804163367835457466111112595890857262", "74312963337095397387789349994033477595", "181327529202719562561631839071146868230" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://gitlab.com/rzkn/libtiff@7be2e452ddcf6d7abca88f41d3761e6edab72b22" } ] }