Vulnerability Details CVE-2020-35524
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2020-35524
-
cpe:2.3:a:libtiff:libtiff:-
-
cpe:2.3:a:libtiff:libtiff:3.4
-
cpe:2.3:a:libtiff:libtiff:3.5.1
-
cpe:2.3:a:libtiff:libtiff:3.5.2
-
cpe:2.3:a:libtiff:libtiff:3.5.3
-
cpe:2.3:a:libtiff:libtiff:3.5.4
-
cpe:2.3:a:libtiff:libtiff:3.5.5
-
cpe:2.3:a:libtiff:libtiff:3.5.6
-
cpe:2.3:a:libtiff:libtiff:3.5.7
-
cpe:2.3:a:libtiff:libtiff:3.6.0
-
cpe:2.3:a:libtiff:libtiff:3.6.1
-
cpe:2.3:a:libtiff:libtiff:3.7.0
-
cpe:2.3:a:libtiff:libtiff:3.7.1
-
cpe:2.3:a:libtiff:libtiff:3.7.2
-
cpe:2.3:a:libtiff:libtiff:3.7.3
-
cpe:2.3:a:libtiff:libtiff:3.7.4
-
cpe:2.3:a:libtiff:libtiff:3.8.0
-
cpe:2.3:a:libtiff:libtiff:3.8.1
-
cpe:2.3:a:libtiff:libtiff:3.8.2
-
cpe:2.3:a:libtiff:libtiff:3.9
-
cpe:2.3:a:libtiff:libtiff:3.9.0
-
cpe:2.3:a:libtiff:libtiff:3.9.1
-
cpe:2.3:a:libtiff:libtiff:3.9.2
-
cpe:2.3:a:libtiff:libtiff:3.9.2-5.2.1
-
cpe:2.3:a:libtiff:libtiff:3.9.3
-
cpe:2.3:a:libtiff:libtiff:3.9.4
-
cpe:2.3:a:libtiff:libtiff:3.9.5
-
cpe:2.3:a:libtiff:libtiff:3.9.6
-
cpe:2.3:a:libtiff:libtiff:3.9.7
-
cpe:2.3:a:libtiff:libtiff:4.0
-
cpe:2.3:a:libtiff:libtiff:4.0.0
-
cpe:2.3:a:libtiff:libtiff:4.0.1
-
cpe:2.3:a:libtiff:libtiff:4.0.10
-
cpe:2.3:a:libtiff:libtiff:4.0.2
-
cpe:2.3:a:libtiff:libtiff:4.0.3
-
cpe:2.3:a:libtiff:libtiff:4.0.3-35
-
cpe:2.3:a:libtiff:libtiff:4.0.4
-
cpe:2.3:a:libtiff:libtiff:4.0.5
-
cpe:2.3:a:libtiff:libtiff:4.0.6
-
cpe:2.3:a:libtiff:libtiff:4.0.7
-
cpe:2.3:a:libtiff:libtiff:4.0.8
-
cpe:2.3:a:libtiff:libtiff:4.0.9
-
cpe:2.3:a:libtiff:libtiff:4.1.0
-
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:33
-
cpe:2.3:o:redhat:enterprise_linux:6.0
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0