PT-2018-3382 · Libtiff+4 · Libtiff+4

Young X

·

Published

2018-09-16

·

Updated

2024-06-15

·

CVE-2018-17101

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LibTIFF version 4.0.9
Description: An issue in LibTIFF can cause a denial of service or possibly have other unspecified impacts via a crafted image file. The issue is related to two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c. This can be exploited by an attacker to cause an application crash or potentially execute arbitrary code using a specially crafted file.
Recommendations: For LibTIFF version 4.0.9, consider avoiding the use of the cpTags function in tools/tiff2bw.c and tools/pal2rgb.c until a patch is available. As a temporary workaround, restrict the processing of crafted image files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00729
CESA-2019_2053
CVE-2018-17101
DLA-1557-1
DSA-4349-1
MGASA-2018-0426
OPENSUSE-SU-2018_3370-1
OPENSUSE-SU-2018_3371-1
OPENSUSE-SU-2024:11461-1
RHSA-2019:2053
RHSA-2019_2053
SUSE-SU-2018:3289-1
SUSE-SU-2018:3327-1
SUSE-SU-2018:3391-1
USN-3864-1
USN-3906-2

Affected Products

Centos
Libtiff
Red Hat
Suse
Ubuntu