NULL pointer dereference in LibTIFF - CVE-2018-19210
Published: December 11, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to insufficient validation of user-supplied input processed by the TIFFWriteDirectorySec function, as defined in the tif_dirwrite.c source code file. A remote attacker can trick the victim into opening or executing a file that submits malicious input, trigger a NULL pointer dereference and cause the service to crash.
Affected software
Gentoo Linux
Slackware Linux
Opensuse
Fedora
tiff (Debian package)
libtiff
How to mitigate CVE-2018-19210
libtiff - addressed in versions 4.0.10-5.fc29, 4.0.10-5.fc30