PT-2018-3382 · Libtiff+4 · Libtiff+4

Young X

·

Publicado

2018-09-16

·

Atualizado

2024-06-15

·

CVE-2018-17101

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LibTIFF version 4.0.9
Description: An issue in LibTIFF can cause a denial of service or possibly have other unspecified impacts via a crafted image file. The issue is related to two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c. This can be exploited by an attacker to cause an application crash or potentially execute arbitrary code using a specially crafted file.
Recommendations: For LibTIFF version 4.0.9, consider avoiding the use of the cpTags function in tools/tiff2bw.c and tools/pal2rgb.c until a patch is available. As a temporary workaround, restrict the processing of crafted image files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00729
CESA-2019_2053
CVE-2018-17101
DLA-1557-1
DSA-4349-1
MGASA-2018-0426
OPENSUSE-SU-2018_3370-1
OPENSUSE-SU-2018_3371-1
OPENSUSE-SU-2024:11461-1
RHSA-2019:2053
RHSA-2019_2053
SUSE-SU-2018:3289-1
SUSE-SU-2018:3327-1
SUSE-SU-2018:3391-1
USN-3864-1
USN-3906-2

Produtos afetados

Centos
Libtiff
Red Hat
Suse
Ubuntu