Back to Database
Status published
High
CVE-2020-19131
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a...
Vulnerability Description
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-19131
Credits & Attribution
No credits recorded in the NVD database.
References
- http://bugzilla.maptools.org/show_bug.cgi?id=2831
- http://blog.topsec.com.cn/%E5%A4%A9%E8%9E%8D%E4%BF%A1%E5%85%B3%E4%BA%8Elibtiff%E4%B8%ADinvertimage%E5%87%BD%E6%95%B0%E5%A0%86%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E%E7%9A%84%E5%88%86%E6%9E%90/
- https://lists.debian.org/debian-lts-announce/2021/10/msg00004.html
Affected Vendor
simplesystems
View all reports →Affected Software
libtiff, debian linux
Vulnerable Versions:
4.0.10, 9.0
Timeline
Official Publish:
September 7th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.