Heap-based buffer over-read in LibTIFF - CVE-2018-10779
Published: May 7, 2018 / Updated: May 21, 2022
Vulnerability identifier: #VU12422
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10779
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in the TIFFWriteScanline function in the tif_write.csource code file due to insufficient validation of user-supplied input. A local attacker can use the .bmp2tiff command to execute a specially crafted file, trigger heap-based buffer over-read and cause the service to crash.
The weakness exists in the TIFFWriteScanline function in the tif_write.csource code file due to insufficient validation of user-supplied input. A local attacker can use the .bmp2tiff command to execute a specially crafted file, trigger heap-based buffer over-read and cause the service to crash.
Affected software
LibTIFF
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
libtiff
Dynamic System Analysis (DSA) Preboot
Data Computing Appliance (DCA)
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
libtiff
Dynamic System Analysis (DSA) Preboot
Data Computing Appliance (DCA)
How to mitigate CVE-2018-10779
Install update from vendor's website.
tiff (Alpine package) - update to 4.0.9-r6
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - addressed in versions 4.0.9-12.fc28, 4.0.9-12.fc29, 4.0.9-13.fc28, 4.0.9-13.fc29
Data Computing Appliance (DCA) - update to 4.3.0.0
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - addressed in versions 4.0.9-12.fc28, 4.0.9-12.fc29, 4.0.9-13.fc28, 4.0.9-13.fc29
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
Related Security Bulletins
- Denial of service in LibTIFF
- Slackware Linux update for libtiff
- Arch Linux update for lib32-libtiff
- OpenSUSE Linux update for tiff
- Red Hat update for libtiff
- Amazon Linux AMI update for libtiff
- Heap-based buffer over-read in tiff (Alpine package)
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
- Fedora 29 update for libtiff
- Fedora 28 update for libtiff
- Fedora 29 update for libtiff
- Fedora 28 update for libtiff