4.3
CVSSv2

CVE-2019-7663

Published: 09/02/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An Invalid Address dereference exists in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 4.0.10

debian debian linux 8.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

canonical ubuntu linux 12.04

opensuse leap 15.0

Vendor Advisories

Several vulnerabilities have been found in the TIFF library, which may result in denial of service or the execution of arbitrary code if malformed image files are processed For the oldstable distribution (stretch), these problems have been fixed in version 408-2+deb9u5 We recommend that you upgrade your tiff packages For the detailed security ...
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file ...
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file ...
An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwritec in LibTIFF 4010, affecting the cpSeparateBufToContigBuf function in tiffcpc Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file ...