NULL pointer dereference in LibTIFF - CVE-2018-7456

 

NULL pointer dereference in LibTIFF - CVE-2018-7456

Published: March 1, 2018 / Updated: March 1, 2018


Vulnerability identifier: #VU10792
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7456
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The vulnerability exists in the TIFFPrintDirectory function that is defined in the tif_print.c source code file due to NULL pointer dereference. A remote attacker can create a specially crafted TIFF file, trick the victim into opening it and cause the service to crash.


Affected software

LibTIFF
Arch Linux
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
openSUSE Leap
libtiff
Dynamic System Analysis (DSA) Preboot
Data Computing Appliance (DCA)

How to mitigate CVE-2018-7456

Install update from vendor's website.

tiff (Alpine package) - update to 4.0.9-r3
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - addressed in versions 4.0.9-8.fc27, 4.0.9-8.fc28
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins