CVE-2018-7456
Summary
| CVE | CVE-2018-7456 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-24 06:29:00 UTC |
| Updated | 2021-01-29 20:15:00 UTC |
| Description | A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.) |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 1346-1] tiff security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1411-1] tiff security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1347-1] tiff3 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| pocs/libtiff at master · xiaoqx/pocs · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Fix NULL pointer dereference in TIFFPrintDirectory (be4c85b1) · Commits · libtiff / libtiff · GitLab |
CONFIRM |
gitlab.com |
Patch, Third Party Advisory |
| USN-3864-1: LibTIFF vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4349-1 tiff |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Bug 2778 – A NULL Pointer Dereference in libtiff (CVE-2018-7456) |
MISC |
bugzilla.maptools.org |
Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377456 Alibaba Cloud Linux Security Update for compat-libtiff3 (ALINUX2-SA-2019:0057)
- 377468 Alibaba Cloud Linux Security Update for libtiff (ALINUX2-SA-2019:0073)
- 500699 Alpine Linux Security Update for tiff
- 504468 Alpine Linux Security Update for tiff