Back

HIGH

libtiff: Memory leaks in tif_open.c, tif_lzw.c, and tif_aux.c

Published Mar 17, 2019

Description

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue

Affected products

Remediation

Red Hat statement

Exploitation of this vulnerability requires that an attacker can cause LibTIFF to process a specially crafted malicious file. This is only possible if a system allows untrusted users to submit images, or alternatively, if a user unknowingly takes an action to process a malicious image. Additionally, successful exploitation will result only in a Denial-of-Service (DoS) to the service or process that incorporates LibTIFF. For those reasons, Red Hat's analysis indicates the overall security impact of this flaw is Low.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 17, 2019
Updated Aug 5, 2024
Reserved Oct 30, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 1, 2017