Back

HIGH

libtiff: Heap-based buffer overflow in ChopUpSingleUncompressedStrip in tif_dirread.c

Published Aug 8, 2018

Description

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf.

Affected products

Remediation

Red Hat statement

Red Hat has determined that this vulnerability has a moderate severity due to a series of factors. Firstly, the attack vector necessary to successfully exploit this flaw is local, given that the attacker must rely on user interaction (by tricking or fooling them into opening a maliciously-crafted TIFF file). Secondly, the CIA impact of this vulnerability should be assumed to be Low for all three vectors, due to to the fact that a successful crash would only impact the LibTIFF application itself, the application does not inherently have access to nor handle sensitive or confidential information, and since it causes a DoS due to heap-based buffer overflow there is little indication that this will modify or alter data. This issue did not affect the versions of libtiff as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 8, 2018
Updated Aug 5, 2024
Reserved Aug 7, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 7, 2018