PT-2019-1952 · Libtiff+2 · Libtiff+2

Zerokeeper

·

Published

2019-01-11

·

Updated

2024-06-15

·

CVE-2019-6128

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.10
Description The issue is related to a memory leak in the TIFFFdOpen function of the LibTIFF library, which can lead to uncontrolled memory allocation. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For LibTIFF version 4.0.10, consider applying a patch or updating to a newer version that fixes the memory leak issue in the TIFFFdOpen function. As a temporary workaround, restrict the use of the TIFFFdOpen function to minimize the risk of exploitation.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01642
CVE-2019-6128
DLA-2009-1
MGASA-2019-0075
OPENSUSE-SU-2019:1161-1
OPENSUSE-SU-2019_1161-1
OPENSUSE-SU-2024:11461-1
SUSE-SU-2019:0786-1
SUSE-SU-2019:14002-1
SUSE-SU-2019:3058-1
SUSE-SU-2019_14002-1
USN-3906-1
USN-3906-2

Affected Products

Libtiff
Suse
Ubuntu