CVE-2018-5360

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
14/01/2018
Last modified:
22/04/2019

Description

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* 4.0.6 (excluding)
cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.27:*:*:*:*:*:*:*