The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://bugzilla.maptools.org/show_bug.cgi?id=2816 | issue tracking exploit third party advisory |
http://www.securityfocus.com/bid/105445 | vdb entry third party advisory |
https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-17795 |