CVE-2024-38806 PUBLISHED CVSS 7.5 HIGH

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

EPSS 0.03% · 8.7th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.03%
8.7th percentile

Affected Products

VendorProductVersions
0
Red HatRed Hat AI Inference Server 3.2sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b, sha256:54616c9f3e4d27120504b0b2020432ef3ff85286a50de7be842f05df0cfcd69e, sha256:dcb9d1cd005c40b6db6f893e56419e383b9dcc0d38315605cb1457e2af5354f7
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat AI Inference Server 3.3sha256:be6d568f28044533e4ad80f0856407c359e2eaf31a6b89cada433e6575d2300e
Red HatRed Hat AI Inference Server 3.2sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7
Red HatRed Hat AI Inference Server 3.3sha256:813ba7ccd1696b44deb90d9e6cd8af114bdb47781eae7f27246a81fba062a892
Red HatRed Hat Enterprise Linux 90:4.4.0-15.el9
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat AI Inference Server 3.2sha256:53007894763e03f609c35c727cb738db3c2130b19fa0e1069c24240e0870fb7a, sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57
Red HatRed Hat AI Inference Server 3.3sha256:0ec114881d9dcd28a5dbbb2ec0ea1301ad87d5ae133121ce8167ef29d19802cc
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:4.6.0-6.el10_0.2
Red HatRed Hat Enterprise Linux 100:4.6.0-6.el10_1.2
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Discovery 2sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740
Red HatRed Hat Enterprise Linux 80:4.0.9-32.el8_10
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:4.4.0-13.el9_6.3
Red HatRed Hat Enterprise Linux 7

Timeline

References

…and 30 more

Open in Interactive Console →