Integer overflow in LibTIFF - CVE-2019-14973
Published: August 26, 2019 / Updated: May 21, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks.
The vulnerability exists due to integer overflow in the "_TIFFCheckMalloc" and "_TIFFCheckRealloc" functions in the "tif_aux.c" file. A remote attacker can trick a victim to open a specially crafted file that contains crafted TIFF images, trigger integer overflow and crash the target application.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Slackware Linux
Ubuntu
Opensuse
Fedora
Ansible Automation Platform
tiff (Alpine package)
libtiff (Red Hat package)
tiff (Debian package)
libtiff5 (Ubuntu package)
libtiff-tools (Ubuntu package)
libtiff
VMware Tanzu Operations Manager
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-14973
tiff (Alpine package) - update to 4.0.10-r1
libtiff (Red Hat package) - addressed in versions 4.0.3-35.el7, 4.0.9-17.el8
tiff (Debian package) - addressed in versions 4.0.8-2+deb9u5, 4.1.0+git191117-2~deb10u1
libtiff5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libtiff-tools (Ubuntu package) - update to Ubuntu Pro (Infra-only)
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
libtiff - addressed in versions 4.0.10-7.fc30, 4.0.10-7.fc31
Red Hat OpenShift Container Platform - update to 4.3.40
External References
Related Security Bulletins
- Denial of service in LibTIFF
- Slackware Linux update for libtiff
- Debian update for tiff
- Red Hat Enterprise Linux 8 update for libtiff
- Debian update for tiff
- Integer overflow in tiff (Alpine package)
- OpenSUSE Linux update for tiff
- Red Hat Enterprise Linux 7 update for libtiff
- OpenSUSE Linux update for tiff
- Amazon Linux AMI update for libtiff
- Ubuntu update for tiff
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- VMware Tanzu Operations Manager update for LibTIFF
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Fedora 30 update for libtiff
- Fedora 31 update for libtiff