CVE-2026-18495

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 18:16

Updated : 2026-09-16 19:42


NVD link : CVE-2026-18495

Mitre link : CVE-2026-18495

CVE.ORG link : CVE-2026-18495


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow