CVE-2018-17000
13.09.2018, 16:29
A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libtiff | libtiff | 4.0.9 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libtiff-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff5 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff5-32bit |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff6 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff6-32bit |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| tiff |
|
Common Weakness Enumeration
References