GHSA-c22p-2vpj-rh5jHighCVSS 7.8

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip...

Published
August 24, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

🔗 References (4)