NULL pointer dereference in LibTIFF - CVE-2017-18013
Published: January 1, 2018 / Updated: January 2, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference error in tif_print.c within TIFFPrintDirectory() function. A remote attacker can trigger a NULL pointer dereference error and crash the affected application.
Affected software
Arch Linux
Amazon Linux AMI
Opensuse
Fedora
tiff (Debian package)
tiff (Alpine package)
openSUSE Leap
libtiff
How to mitigate CVE-2017-18013
tiff (Alpine package) - update to 4.0.9-r1
libtiff - addressed in versions 4.0.9-9.fc27, 4.0.9-9.fc28
External References
Related Security Bulletins
- NULL pointer dereference in LibTIFF
- Multiple vulnerabilities in LibTIFF
- OpenSUSE Linux update for tiff
- OpenSUSE Linux update for tiff
- Debian update for tiff
- Arch Linux update for lib32-libtiff
- Amazon Linux AMI update for libtiff
- NULL pointer dereference in tiff (Alpine package)
- Fedora 27 update for libtiff
- Fedora 28 update for libtiff