CVE-2024-7006: Fixes in libtiff
A null pointer dereference flaw was found in Libtiff via tifdirinfo.c. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
Other sources
A null pointer dereference issue was found in Libtiff's tifdirinfo.c file. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or just injecting faults, which would cause segmentation fault. This may cause an application crash, eventually leading to a denial of service.
References: https://gitlab.com/libtiff/libtiff/-/mergerequests/559 https://gitlab.com/libtiff/libtiff/-/issues/624
— Red Hat
LibTIFF is vulnerable to a denial of service, caused by a NULL pointer dereference flaw tifdirinfo.c. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause application to crash.
— IBM
Libtiff: null pointer dereference in tifdirinfo.c
— Microsoft
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7006?
CVE-2024-7006 is classified as a moderate severity vulnerability due to the potential for causing memory allocation failures.
How do I fix CVE-2024-7006?
To fix CVE-2024-7006, upgrade the affected software versions to the patched releases or apply the available patches from the vendor.
Which software is affected by CVE-2024-7006?
CVE-2024-7006 affects various versions of Libtiff and IBM Cognos Analytics, as well as specific versions of Red Hat Enterprise Linux.
What type of vulnerability is CVE-2024-7006?
CVE-2024-7006 is a null pointer dereference vulnerability that can lead to segmentation faults and application crashes.
Can CVE-2024-7006 be exploited remotely?
Yes, CVE-2024-7006 can potentially be exploited remotely if an attacker can manipulate the data processed by the affected software.