ISOMAN

CVE

CVE-2018-7456

A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://bugzilla.maptools.org/show_bug.cgi?id=2778
  2. https://access.redhat.com/errata/RHSA-2019:2051
  3. https://access.redhat.com/errata/RHSA-2019:2053
  4. https://github.com/xiaoqx/pocs/tree/master/libtiff
  5. https://gitlab.com/libtiff/libtiff/commit/be4c85b16e8801a16eec25e80eb9f3dd6a96731b
  6. https://lists.debian.org/debian-lts-announce/2018/04/msg00010.html
  7. https://lists.debian.org/debian-lts-announce/2018/04/msg00011.html
  8. https://lists.debian.org/debian-lts-announce/2018/07/msg00002.html
  9. https://usn.ubuntu.com/3864-1/
  10. https://www.debian.org/security/2018/dsa-4349
  11. http://bugzilla.maptools.org/show_bug.cgi?id=2778
  12. https://access.redhat.com/errata/RHSA-2019:2051
  13. https://access.redhat.com/errata/RHSA-2019:2053
  14. https://github.com/xiaoqx/pocs/tree/master/libtiff
  15. https://gitlab.com/libtiff/libtiff/commit/be4c85b16e8801a16eec25e80eb9f3dd6a96731b
  16. https://lists.debian.org/debian-lts-announce/2018/04/msg00010.html
  17. https://lists.debian.org/debian-lts-announce/2018/04/msg00011.html
  18. https://lists.debian.org/debian-lts-announce/2018/07/msg00002.html
  19. https://usn.ubuntu.com/3864-1/
  20. https://www.debian.org/security/2018/dsa-4349