First published: Sat Apr 21 2018(Updated: )
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tiff | =4.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10126 is considered a high-severity vulnerability due to its potential to cause a denial of service through NULL pointer dereference.
To fix CVE-2018-10126, upgrade to LibTIFF version 4.0.10 or later where the issue has been resolved.
CVE-2018-10126 affects LibTIFF version 4.0.9 and earlier versions utilizing the ijg-libjpeg library.
CVE-2018-10126 is a NULL pointer dereference vulnerability located in the jpeg_fdct_16x16 function of jfdctint.c.
More details about CVE-2018-10126 can be found in the related bug tracking reports and security documentation specific to LibTIFF.