A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
Workaround:
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:6360 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2024:8833 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:8914 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-7006 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2302996 | issue tracking |
https://security.netapp.com/advisory/ntap-20240920-0001/ |