← Vulnerability feed

Vulnerability record · CVE-2019-17546 · published 14 October 2019

CVE-2019-17546: Libtiff integer overflow vulnerability

Libtiff · Libtiff

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

8.8 CVSS 3.1 High EPSS 3.4% · top 11.7% CWE-190 · Integer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
23References
17 Jun 2026Last modified by NVD

Description

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443 Third Party Advisory
https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf PatchThird Party Advisory
https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145 PatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/03/msg00020.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LM5ZW7E3IEW7LT2BPJP7D3R
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M3S4WNIMZ7XSLY2LD5FPRPZ
https://seclists.org/bugtraq/2020/Jan/32
https://security.gentoo.org/glsa/202003-25
https://www.debian.org/security/2020/dsa-4608
https://www.debian.org/security/2020/dsa-4670
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443 Third Party Advisory
https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf PatchThird Party Advisory
https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145 PatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/03/msg00020.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LM5ZW7E3IEW7LT2BPJP7D3R
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M3S4WNIMZ7XSLY2LD5FPRPZ
https://seclists.org/bugtraq/2020/Jan/32
https://security.gentoo.org/glsa/202003-25
https://security.netapp.com/advisory/ntap-20241220-0007/
https://www.debian.org/security/2020/dsa-4608
https://www.debian.org/security/2020/dsa-4670

Track CVE-2019-17546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0929Libtiff vulnerabilityHeap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPE…EPSS 8.2%10.0CVE-2004-1308Libtiff vulnerabilityInteger overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF fil…EPSS 15%9.8CVE-2019-17545Osgeo gdal double free vulnerabilityGDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.EPSS 2.6%9.8CVE-2016-9540Libtiff memory buffer overflow vulnerabilitytools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStr…EPSS 3.6%9.8CVE-2016-9539Libtiff memory buffer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.EPSS 3.0%9.8CVE-2016-9538Libtiff integer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35…EPSS 3.4%9.8CVE-2016-9537Libtiff memory buffer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.EPSS 3.1%9.8CVE-2016-9536Libtiff memory buffer overflow vulnerabilitytools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 350…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2019-17546), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.