CVE-2018-12900

Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libtiff:libtiff:4.0.9:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

History

21 Nov 2024, 03:46

Type Values Removed Values Added
References () http://bugzilla.maptools.org/show_bug.cgi?id=2798 - Exploit, Issue Tracking, Third Party Advisory () http://bugzilla.maptools.org/show_bug.cgi?id=2798 - Exploit, Issue Tracking, Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2053 - () https://access.redhat.com/errata/RHSA-2019:2053 -
References () https://access.redhat.com/errata/RHSA-2019:3419 - () https://access.redhat.com/errata/RHSA-2019:3419 -
References () https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-12900 - () https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-12900 -
References () https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html - () https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html -
References () https://usn.ubuntu.com/3906-1/ - Third Party Advisory () https://usn.ubuntu.com/3906-1/ - Third Party Advisory
References () https://usn.ubuntu.com/3906-2/ - () https://usn.ubuntu.com/3906-2/ -
References () https://www.debian.org/security/2020/dsa-4670 - () https://www.debian.org/security/2020/dsa-4670 -

Information

Published : 2018-06-26 22:29

Updated : 2024-11-21 03:46


NVD link : CVE-2018-12900

Mitre link : CVE-2018-12900

CVE.ORG link : CVE-2018-12900


JSON object : View

Products Affected

canonical

  • ubuntu_linux

libtiff

  • libtiff
CWE
CWE-787

Out-of-bounds Write