CVE-2018-10963: Medium severity LibTIFF libtiff vulnerability
A flaw was found in LibTIFF through 4.0.9. TIFFWriteDirectorySec() function in tifdirwrite.c allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file.
References: http://bugzilla.maptools.org/showbug.cgi?id=2795
Patch: https://gitlab.com/libtiff/libtiff/commit/de144fd228e4be8aa484c3caf3d814b6fa88c6d9
Other sources
The TIFFWriteDirectorySec() function in tifdirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1 - Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Fixed in 4.0.9Patch de144fd228e4be8aa484c3caf3d814b6fa88c6d9 - Compensating control
Mitigate the denial-of-service vector by restricting access so remote attackers cannot supply crafted TIFF files to systems/processes that use LibTIFF (e.g., block untrusted uploads/ingestion paths at the network/WAF/ACL layer).
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10963?
CVE-2018-10963 is classified as a denial of service vulnerability due to application crashes caused by crafted TIFF files.
How do I fix CVE-2018-10963?
To fix CVE-2018-10963, update LibTIFF to version 4.0.10 or higher to avoid the vulnerability.
Which software is affected by CVE-2018-10963?
CVE-2018-10963 affects LibTIFF versions up to 4.0.9 and may affect various distributions that include this library.
What type of attack can exploit CVE-2018-10963?
CVE-2018-10963 can be exploited through the delivery of crafted TIFF files that cause application crashes.
Is CVE-2018-10963 fixed in my Debian or Ubuntu system?
Check if your Debian or Ubuntu system has updated LibTIFF to version 4.0.10 or later to ensure CVE-2018-10963 is fixed.