← Back to CVE search

CVE-2026-52492

libtiff

Description

An integer overflow in the libtiff rgb2ycbcr utility-s cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

CVSS 7.8EPSS 0.13%Risk 0.79
View source
Published
2026-08-24 21:17:19
Affected versions
unknown
Type
Library
Last modified
2026-08-27 20:17:48
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H