Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19210

Опубликовано: 28 окт. 2018
Источник: redhat
CVSS3: 3.3

Описание

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

A vulnerability was found in LibTIFF due to a NULL pointer dereference in the TIFFWriteDirectorySec function within tif_dirwrite.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash and resulting in a denial of service condition.

Отчет

This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file. While it does not allow full system compromise, it can cause the application to crash temporarily.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 6libtiffWill not fix
Red Hat Enterprise Linux 7compat-libtiff3Will not fix
Red Hat Enterprise Linux 7libtiffWill not fix
Red Hat Enterprise Linux 8libtiffWill not fix
Red Hat Enterprise Linux 8mingw-libtiffFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1649385libtiff: NULL pointer dereference in TIFFWriteDirectorySec function in tif_dirwrite.c

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

CVSS3: 6.5
nvd
больше 7 лет назад

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

CVSS3: 6.5
debian
больше 7 лет назад

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWrite ...

CVSS3: 6.5
github
почти 4 года назад

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции TIFFWriteDirectorySec программного обеспечения для просмотра, редактирования и конвертирования TIFF-файлов, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3