Memory leak in LibTIFF - CVE-2019-6128
Published: January 16, 2019 / Updated: May 21, 2022
Vulnerability identifier: #VU17016
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6128
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in TIFFFdOpen function in tif_unix.c. A remote attacker can trigger memory leak and perform denial of service attack.
Affected software
LibTIFF
Arch Linux
Gentoo Linux
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
libtiff
Arch Linux
Gentoo Linux
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
libtiff
How to mitigate CVE-2019-6128
Install update from vendor's website.
tiff (Alpine package) - update to 4.0.10-r3
libtiff - update to 4.0.10-2.fc29
libtiff - update to 4.0.10-2.fc29