CVE-2019-7663
09.02.2019, 16:29
An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libtiff | libtiff | 4.0.10 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| opensuse | leap | 15.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium |
| ||||||||||||||||||||||||||||||
| gdal |
| ||||||||||||||||||||||||||||||
| openjpeg2 |
| ||||||||||||||||||||||||||||||
| qt4-x11 |
| ||||||||||||||||||||||||||||||
| qtimageformats-opensource-src |
| ||||||||||||||||||||||||||||||
| qtwebengine-opensource-src |
| ||||||||||||||||||||||||||||||
| texmaker |
| ||||||||||||||||||||||||||||||
| tiff |
| ||||||||||||||||||||||||||||||
| tiff3 |
|
References