CVE-2018-18557
Summary
| CVE | CVE-2018-18557 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-22 16:29:00 UTC |
| Updated | 2021-03-05 18:15:00 UTC |
| Description | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode out-of-bounds write. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Pocs_for_Multi_Versions/CVE-2018-18557 at main · Hack-Me/Pocs_for_Multi_Versions · GitHub |
MISC |
github.com |
|
| USN-3906-2: LibTIFF vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] [DLA 1557-1] tiff security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| libtiff 4.0.9 - Decodes Arbitrarily Sized JBIG into a Target Buffer - Linux dos Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| JBIG: fix potential out-of-bounds write in JBIGDecode() (681748ec) · Commits · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| USN-3864-1: LibTIFF vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4349-1 tiff |
DEBIAN |
www.debian.org |
Third Party Advisory |
| libTIFF: Denial of Service (GLSA 201904-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| JBIG: fix potential out-of-bounds write in JBIGDecode() (!38) · Merge Requests · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377468 Alibaba Cloud Linux Security Update for libtiff (ALINUX2-SA-2019:0073)
- 500690 Alpine Linux Security Update for tiff
- 504459 Alpine Linux Security Update for tiff
- 710169 Gentoo Linux libTIFF Denial of service Vulnerability (GLSA 201904-15)