Integer overflow in LibTIFF - CVE-2019-14973

 

Integer overflow in LibTIFF - CVE-2019-14973

Published: August 26, 2019 / Updated: May 21, 2022


Vulnerability identifier: #VU20390
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14973
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks.

The vulnerability exists due to integer overflow in the "_TIFFCheckMalloc" and "_TIFFCheckRealloc" functions in the "tif_aux.c" file. A remote attacker can trick a victim to open a specially crafted file that contains crafted TIFF images, trigger integer overflow and crash the target application.



Affected software

LibTIFF
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Slackware Linux
Ubuntu
Opensuse
Fedora
Ansible Automation Platform
tiff (Alpine package)
libtiff (Red Hat package)
tiff (Debian package)
libtiff5 (Ubuntu package)
libtiff-tools (Ubuntu package)
libtiff
VMware Tanzu Operations Manager
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-14973

Install update from vendor's website.

Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
tiff (Alpine package) - update to 4.0.10-r1
libtiff (Red Hat package) - addressed in versions 4.0.3-35.el7, 4.0.9-17.el8
tiff (Debian package) - addressed in versions 4.0.8-2+deb9u5, 4.1.0+git191117-2~deb10u1
libtiff5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libtiff-tools (Ubuntu package) - update to Ubuntu Pro (Infra-only)
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
libtiff - addressed in versions 4.0.10-7.fc30, 4.0.10-7.fc31
Red Hat OpenShift Container Platform - update to 4.3.40

External References

Related Security Bulletins