Memory leak in LibTIFF - CVE-2019-6128

 

Memory leak in LibTIFF - CVE-2019-6128

Published: January 16, 2019 / Updated: May 21, 2022


Vulnerability identifier: #VU17016
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6128
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in TIFFFdOpen function in tif_unix.c. A remote attacker can trigger memory leak and perform denial of service attack.


Affected software

LibTIFF
Arch Linux
Gentoo Linux
Slackware Linux
Opensuse
Fedora
tiff (Alpine package)
libtiff

How to mitigate CVE-2019-6128

Install update from vendor's website.

tiff (Alpine package) - update to 4.0.10-r3
libtiff - update to 4.0.10-2.fc29

External References

Related Security Bulletins