NULL pointer dereference in LibTIFF - CVE-2018-17000
Published: May 15, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction). A remote attacker can create a specially crafted tiff file and perform a denial of service (DoS) attack.
Affected software
tiff (Debian package)
Opensuse
How to mitigate CVE-2018-17000
tiff (Debian package) - update to 4.0.8-2+deb9u5