Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-6716

Published: July 15, 2024Last modified: June 17, 2025

Description

A flaw was found in libtiff. This flaw allows an attacker to create a crafted tiff file, forcing libtiff to allocate memory indefinitely. This issue can result in a denial of service of the system consuming libtiff due to memory starvation.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Notes

Per tiff upstream it's not a valid security issue, but a misuse of the API.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTStiffWill not fix (4.4.0-r1)
StreamtiffWill not fix (4.4.0-r1)

References

ON THIS PAGE