A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in...
Vulnerability Description
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-7456
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.debian.org/debian-lts-announce/2018/04/msg00011.html
- https://usn.ubuntu.com/3864-1/
- https://www.debian.org/security/2018/dsa-4349
- https://github.com/xiaoqx/pocs/tree/master/libtiff
- http://bugzilla.maptools.org/show_bug.cgi?id=2778
- https://lists.debian.org/debian-lts-announce/2018/07/msg00002.html
- https://lists.debian.org/debian-lts-announce/2018/04/msg00010.html
- https://gitlab.com/libtiff/libtiff/commit/be4c85b16e8801a16eec25e80eb9f3dd6a96731b
- https://access.redhat.com/errata/RHSA-2019:2051
- https://access.redhat.com/errata/RHSA-2019:2053
More from libtiff
View All →Affected Vendor
libtiff
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.