NULL pointer dereference in LibTIFF - CVE-2017-18013

 

NULL pointer dereference in LibTIFF - CVE-2017-18013

Published: January 1, 2018 / Updated: January 2, 2018


Vulnerability identifier: #VU9820
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18013
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference error in tif_print.c within TIFFPrintDirectory() function. A remote attacker can trigger a NULL pointer dereference error and crash the affected application.


Affected software

LibTIFF
Arch Linux
Amazon Linux AMI
Opensuse
Fedora
tiff (Debian package)
tiff (Alpine package)
openSUSE Leap
libtiff

How to mitigate CVE-2017-18013

Install update from vendor's website.

tiff (Debian package) - update to 4.0.8-2+deb9u2
tiff (Alpine package) - update to 4.0.9-r1
libtiff - addressed in versions 4.0.9-9.fc27, 4.0.9-9.fc28

External References

Related Security Bulletins