HIGH
libtiff: Integer overflow in multiply_ms in tools/ppm2tiff.c
Published Sep 16, 2018
8.8
HIGHCVSS 3.0
EPSS 2.47%
Description
An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.
Affected products
No data.
Configuration 1
- 8.0
Configuration 3
OR
- 14.04
- 16.04
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 7
libtiff-0:4.0.3-32.el7
Fixed · RHSA-2019:2053
Red Hat Enterprise Linux 5
libtiff
Will not fix
Red Hat Enterprise Linux 6
libtiff
Will not fix
Red Hat Enterprise Linux 7
compat-libtiff3
Will not fix
Red Hat Enterprise Linux 8
libtiff
Not affected
Red Hat Enterprise Linux 8
mingw-libtiff
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libtiff-0:4.0.3-32.el7 | Fixed | RHSA-2019:2053 |
| Red Hat Enterprise Linux 5 | libtiff | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libtiff | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | libtiff | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-libtiff | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (11)
- http://bugzilla.maptools.org/show_bug.cgi?id=2810 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2053 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-17100 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1631069 Issue Tracking
- https://gitlab.com/libtiff/libtiff/merge_requests/33/diffs?commit_id=6da1fb3f64d43be37e640efbec60400d1f1ac39e x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00019.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-17100
- https://usn.ubuntu.com/3864-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3906-2/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-17100
- https://www.debian.org/security/2020/dsa-4670 vendor-advisoryx_refsource_DEBIAN
| Link | Providers | Tags |
|---|---|---|
| http://bugzilla.maptools.org/show_bug.cgi?id=2810 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:2053 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-17100 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1631069 | Issue Tracking | |
| https://gitlab.com/libtiff/libtiff/merge_requests/33/diffs?commit_id=6da1fb3f64d43be37e640efbec60400d1f1ac39e | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2018/10/msg00019.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-17100 | ||
| https://usn.ubuntu.com/3864-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3906-2/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2018-17100 | ||
| https://www.debian.org/security/2020/dsa-4670 | vendor-advisoryx_refsource_DEBIAN |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 16, 2018
Updated Aug 5, 2024
Reserved Sep 16, 2018
Link CVE-2018-17100
CISA Vulnrichment
Updated n/a