Heap-based buffer over-read in LibTIFF - CVE-2018-10779

 

Heap-based buffer over-read in LibTIFF - CVE-2018-10779

Published: May 7, 2018 / Updated: May 21, 2022


Vulnerability identifier: #VU12422
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10779
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the TIFFWriteScanline function in the tif_write.csource code file due to insufficient validation of user-supplied input. A local attacker can use the .bmp2tiff command to execute a specially crafted file, trigger heap-based buffer over-read and cause the service to crash.


Affected software

LibTIFF
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
libtiff
Dynamic System Analysis (DSA) Preboot
Data Computing Appliance (DCA)

How to mitigate CVE-2018-10779

Install update from vendor's website.

tiff (Alpine package) - update to 4.0.9-r6
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - addressed in versions 4.0.9-12.fc28, 4.0.9-12.fc29, 4.0.9-13.fc28, 4.0.9-13.fc29
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins