LibTIFF CVE-2018-18557 Memory Corruption Vulnerability
BID:105749
Info
LibTIFF CVE-2018-18557 Memory Corruption Vulnerability
| Bugtraq ID: | 105749 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-18557 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2018 12:00AM |
| Updated: | Oct 13 2018 12:00AM |
| Credit: | Thomas Dullien |
| Vulnerable: |
LibTIFF LibTIFF 4.0.9 LibTIFF LibTIFF 4.0.8 LibTIFF LibTIFF 4.0.3 LibTIFF LibTIFF 4.0.2 LibTIFF LibTIFF 3.9.4 LibTIFF LibTIFF 3.9.3 LibTIFF LibTIFF 3.9.2 LibTIFF LibTIFF 3.9 LibTIFF LibTIFF 3.8.2 LibTIFF LibTIFF 3.8.1 LibTIFF LibTIFF 3.8 LibTIFF LibTIFF 3.7.4 LibTIFF LibTIFF 3.7.3 LibTIFF LibTIFF 3.7.2 LibTIFF LibTIFF 3.7.1 LibTIFF LibTIFF 3.7 LibTIFF LibTIFF 3.6.1 LibTIFF LibTIFF 3.6 LibTIFF LibTIFF 3.5.7 LibTIFF LibTIFF 3.5.6 LibTIFF LibTIFF 3.5.5 LibTIFF LibTIFF 3.5.4 LibTIFF LibTIFF 3.5.3 LibTIFF LibTIFF 3.5.2 LibTIFF LibTIFF 3.5.1 LibTIFF LibTIFF 3.4 LibTIFF LibTIFF 4.0.7 LibTIFF LibTIFF 4.0.6 LibTIFF LibTIFF 4.0.5 LibTIFF LibTIFF 4.0.4 LibTIFF LibTIFF 4.0.1 LibTIFF LibTIFF 4.0 LibTIFF LibTIFF 3.9.5 LibTIFF LibTIFF 3.9.1 LibTIFF LibTIFF 3.9 LibTIFF LibTIFF 3.7.2-7 LibTIFF LibTIFF 3.4 |
| Not Vulnerable: | |
Discussion
LibTIFF CVE-2018-18557 Memory Corruption Vulnerability
LibTIFF is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue to execute arbitrary code in the context of the application using the affected library. Failed exploit attempts may result in denial-of-service conditions.
LibTIFF 4.0.9 and prior versions are vulnerable.
LibTIFF is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue to execute arbitrary code in the context of the application using the affected library. Failed exploit attempts may result in denial-of-service conditions.
LibTIFF 4.0.9 and prior versions are vulnerable.
Exploit / POC
LibTIFF CVE-2018-18557 Memory Corruption Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
LibTIFF CVE-2018-18557 Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.