CVE-2019-7663
09.02.2019, 16:29
An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.Enginsight
Vendor | Product | Version |
---|---|---|
libtiff | libtiff | 4.0.10 |
debian | debian_linux | 8.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
opensuse | leap | 15.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium |
| ||||||||||||||||||||||||||||||
gdal |
| ||||||||||||||||||||||||||||||
openjpeg2 |
| ||||||||||||||||||||||||||||||
qt4-x11 |
| ||||||||||||||||||||||||||||||
qtimageformats-opensource-src |
| ||||||||||||||||||||||||||||||
qtwebengine-opensource-src |
| ||||||||||||||||||||||||||||||
texmaker |
| ||||||||||||||||||||||||||||||
tiff |
| ||||||||||||||||||||||||||||||
tiff3 |
|
References