CyberRota Analysis
AI-GeneratedThe `tiffload` operation in libvips versions up to and including 8.18.1 is vulnerable to a buffer overflow due to incorrect channel determination in JPEG or JPEG2000-encoded tiles within TIFF images. This vulnerability could potentially allow an attacker to execute arbitrary code or crash the application. Users and developers relying on libvips for image processing should prioritize upgrading to version 8.18.2 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.