4.3
CVSSv2

CVE-2018-19210

Published: 12/11/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

It exists that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 4.0.9

debian debian linux 8.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #921157 tiff: CVE-2019-6128 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Feb 2019 13:09:01 UTC Severity: normal Tags: security, upstream Found in version tiff/4010-3 Fixed in ver ...
Debian Bug report logs - #902718 CVE-2018-12900 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 29 Jun 2018 21:03:01 UTC Severity: important Tags: security, upstream Found in version tiff/409-1 Fixed in version tif ...
Debian Bug report logs - #913675 tiff: CVE-2018-19210 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 13 Nov 2018 22:24:01 UTC Severity: important Tags: security, upstream Found in version tiff/409+git181026-1 ...
Debian Bug report logs - #908778 tiff: CVE-2018-17000: null pointer deference flaw Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 13 Sep 2018 20:39:02 UTC Severity: important Tags: security, upstream Found in v ...
Several vulnerabilities have been found in the TIFF library, which may result in denial of service or the execution of arbitrary code if malformed image files are processed For the oldstable distribution (stretch), these problems have been fixed in version 408-2+deb9u5 We recommend that you upgrade your tiff packages For the detailed security ...
In LibTIFF 409, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwritec that will lead to a denial of service attack, as demonstrated by tiffset ...