6.8
CVSSv2

CVE-2018-15209

Published: 08/08/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote malicious users to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 4.0.9

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #905798 tiff: CVE-2018-15209 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 9 Aug 2018 20:36:01 UTC Severity: important Tags: security, upstream Found in versions tiff/408-2+deb9u2, ...
Debian Bug report logs - #907795 tiff: CVE-2018-16335: heap-buffer-overflow Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 2 Sep 2018 09:00:02 UTC Severity: important Tags: security, upstream Found in versions ...
Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed For the stable distribution (stretch), these problems have been fixed in version 408-2+deb9u4 We recommend that you upgrade your tiff package ...
ChopUpSingleUncompressedStrip in tif_dirreadc in LibTIFF 409 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf ...