PT-2018-3345 · Libtiff+4 · Libtiff+4

Salvatore Bonaccorso

·

Published

2018-10-25

·

Updated

2024-06-15

·

CVE-2018-18661

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: LibTIFF version 4.0.9
Description: The issue is related to a NULL pointer dereference in the LZWDecode function. This can be exploited by a remote attacker using a specially crafted graphic file, potentially allowing the execution of arbitrary code or causing a denial of service.
Recommendations: For LibTIFF version 4.0.9, consider disabling the LZWDecode function as a temporary workaround until a patch is available. Restrict the use of LibTIFF to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00196
CESA-2019_2053
CVE-2018-18661
DLA-2009-1
MGASA-2018-0444
OPENSUSE-SU-2018_3947-1
OPENSUSE-SU-2018_3948-1
OPENSUSE-SU-2024:11461-1
RHSA-2019:2053
RHSA-2019_2053
SUSE-SU-2018:3879-1
SUSE-SU-2018:3911-1
SUSE-SU-2018:3911-2
SUSE-SU-2018:3925-1
USN-3864-1

Affected Products

Centos
Libtiff
Red Hat
Suse
Ubuntu