PT-2018-3526 · Libtiff+2 · Libtiff+2

Ganshuitao

·

Published

2018-11-12

·

Updated

2024-06-15

·

CVE-2018-19210

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: LibTIFF version 4.0.9
Description: The issue is related to a NULL pointer dereference in the TIFFWriteDirectorySec function, which can lead to a denial of service attack. This can be exploited by a remote attacker to cause a service disruption.
Recommendations: For LibTIFF version 4.0.9, consider applying a patch or update that fixes the NULL pointer dereference issue in the TIFFWriteDirectorySec function. As a temporary workaround, restrict the use of the TIFFWriteDirectorySec function until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03280
CVE-2018-19210
DLA-1680-1
DSA-4670-1
MGASA-2018-0493
OPENSUSE-SU-2018_4053-1
OPENSUSE-SU-2018_4256-1
OPENSUSE-SU-2019:1161-1
OPENSUSE-SU-2019_1161-1
OPENSUSE-SU-2024:11461-1
SUSE-SU-2018:4008-1
SUSE-SU-2018:4191-1
SUSE-SU-2019:0786-1
USN-3906-1

Affected Products

Libtiff
Suse
Ubuntu