#VU13373 Input validation error in LibTIFF - CVE-2018-10963
Published: June 16, 2018 / Updated: June 17, 2018
LibTIFF
LibTIFF
Description
The vulnerability allows a remote attacker to cause denial of service conditions.
The vulnerability exists due to insufficient validation of user-supplied input processed by the TIFFWriteDirectorySec() function, as defined in the tif_dirwrite.c source code file. A remote attacker can trick the victim into opening a specially crafted file, trigger assertion failure and cause the application to crash.