Back

HIGH

libtiff: Heap-based buffer overflow in ChopUpSingleUncompressedStrip in tif_dirread.c

Published Sep 2, 2018

Description

newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. This is a different vulnerability than CVE-2018-15209.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as moderate because it allows an attacker to cause a denial of service through a heap-based buffer overflow, exploiting this flaw would crash the application, impacting its availability but not leading to further system compromise.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 2, 2018
Updated Aug 5, 2024
Reserved Sep 1, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 7, 2018