PT-2019-4385 · Libtiff+5 · Libtiff+5

Even Rouault

·

Published

2019-04-10

·

Updated

2024-06-15

·

CVE-2019-14973

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF versions through 4.0.10
Description The issue arises from integer overflow checks in the TIFFCheckMalloc and TIFFCheckRealloc functions within tif aux.c of the LibTIFF library. This can lead to an application crash. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions through 4.0.10, consider updating to a version that addresses the integer overflow issue in the TIFFCheckMalloc and TIFFCheckRealloc functions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1628
BDU:2020-00107
CESA-2020_1688
CESA-2020_3902
CVE-2019-14973
DLA-1897-1
DSA-4608-1
DSA-4670-1
OPENSUSE-SU-2020:1561-1
OPENSUSE-SU-2020:1840-1
OPENSUSE-SU-2020_1561-1
OPENSUSE-SU-2020_1840-1
OPENSUSE-SU-2024:13381-1
RHSA-2020:1688
RHSA-2020:3902
RHSA-2020_1688
RHSA-2020_3902
SUSE-SU-2019:3058-1
SUSE-SU-2020:2744-1
SUSE-SU-2020_2744-1
USN-4158-1
USN-5841-1

Affected Products

Alt Linux
Centos
Libtiff
Red Hat
Suse
Ubuntu