libtiff: memory leak in TIFFFdOpen function in tif_unix.c when using pal2rgb
Published Jan 11, 2019
8.8
HIGHCVSS 3.1
EPSS 3.85%
Description
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
Affected products
No data.
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 4
- 8.0
No data.
Red Hat Enterprise Linux 5
libtiff
Will not fix
Red Hat Enterprise Linux 6
libtiff
Will not fix
Red Hat Enterprise Linux 7
libtiff
Will not fix
Red Hat Enterprise Linux 8
libtiff
Will not fix
Red Hat Enterprise Linux 8
mingw-libtiff
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libtiff | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libtiff | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libtiff | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | libtiff | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | mingw-libtiff | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated as moderate because a memory leak in LibTIFF’s TIFFFdOpen function within tif_unix.c could lead to a denial of service, exploitation requires user interaction, as an attacker must persuade a victim to open a specially crafted file. While this does not lead to code execution, repeated exploitation could impact application availability.
Red Hat mitigation
This bug could be mitigated by configuring process memory limits using cgroups.
References (14)
- http://bugzilla.maptools.org/show_bug.cgi?id=2836 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/155095/Slackware-Security-Advisory-libtiff-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-6128 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1667122 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15695 Advisory
- https://gitlab.com/libtiff/libtiff/commit/0c74a9f49b8d7a36b17b54a7428b3526d20f88a8 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-6128
- https://seclists.org/bugtraq/2019/Nov/5 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-25 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/3906-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3906-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-6128
Change history (0)
No recorded changes yet.