There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://bugzilla.maptools.org/show_bug.cgi?id=2848 | third party advisory issue tracking exploit |