Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2009-1 | tiff security update |
Debian DSA |
DSA-4670-1 | tiff security update |
Ubuntu USN |
USN-3906-1 | LibTIFF vulnerabilities |
Ubuntu USN |
USN-3906-2 | LibTIFF vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:45:02.541Z
Reserved: 2018-06-26T00:00:00
Link: CVE-2018-12900
No data.
Status : Modified
Published: 2018-06-26T22:29:00.257
Modified: 2024-11-21T03:46:03.900
Link: CVE-2018-12900
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN