CVE-2019-17546
Summary
| CVE | CVE-2019-17546 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-14 02:15:00 UTC |
| Updated | 2023-11-07 03:06:00 UTC |
| Description | tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition. |
Risk And Classification
Problem Types: CWE-787 | CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 31 Update: libtiff-4.0.10-8.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| RGBA interface: fix integer overflow potentially causing write heap buffer... (4bb584a3) · Commits · libtiff / libtiff · GitLab | MISC | gitlab.com | Patch, Third Party Advisory |
| libTIFF: Multiple vulnerabilities (GLSA 202003-25) — Gentoo security | GENTOO | security.gentoo.org | |
| Bugtraq: [SECURITY] [DSA 4608-1] tiff security update | BUGTRAQ | seclists.org | |
| 16443 - oss-fuzz - OSS-Fuzz: Fuzzing the planet - Monorail | MISC | bugs.chromium.org | Third Party Advisory |
| [SECURITY] [DLA 2009-1] tiff security update | MLIST | lists.debian.org | Third Party Advisory |
| [SECURITY] Fedora 30 Update: libtiff-4.0.10-8.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 2147-1] gdal security update | MLIST | lists.debian.org | |
| Internal libtiff: fix integer overflow potentially causing write heap… · OSGeo/gdal@2167403 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4608-1 tiff | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 30 Update: libtiff-4.0.10-8.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 31 Update: libtiff-4.0.10-8.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-4670-1 tiff | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199525 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-5841-1)
- 296078 Oracle Solaris 11.4 Support Repository Update (SRU) 16.4.0 Missing (CPUOCT2019)
- 377286 Alibaba Cloud Linux Security Update for libtiff (ALINUX2-SA-2020:0130)
- 377418 Alibaba Cloud Linux Security Update for libtiff (ALINUX3-SA-2022:0105)
- 671104 EulerOS Security Update for libtiff (EulerOS-SA-2019-2707)
- 751716 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:0480-1)
- 751721 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:0496-1)
- 751752 OpenSUSE Security Update for tiff (openSUSE-SU-2022:0480-1)
- 940309 AlmaLinux Security Update for libtiff (ALSA-2020:4634)
- 960802 Rocky Linux Security Update for libtiff (RLSA-2020:4634)