CVE-2018-16335: Buffer Overflow
LibTIFF is vulnerable to a denial of service, caused by a heap-baesd buffer overflow in the newoffsets handling in ChopUpSingleUncompressedStrip in tifdirread.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
newoffsets handling in ChopUpSingleUncompressedStrip in tifdirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. This is a different vulnerability than CVE-2018-15209.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16335?
CVE-2018-16335 is classified as a denial of service vulnerability.
How do I fix CVE-2018-16335?
To mitigate CVE-2018-16335, users should upgrade to the patched versions of LibTIFF, IBM Cognos Analytics, or Debian as specified in the respective vendor advisories.
What causes CVE-2018-16335?
CVE-2018-16335 is caused by a heap-based buffer overflow in the handling of newoffsets in the ChopUpSingleUncompressedStrip function.
Which software is affected by CVE-2018-16335?
CVE-2018-16335 affects LibTIFF, IBM Cognos Analytics, and various Debian packages.
Can CVE-2018-16335 be exploited remotely?
Yes, a remote attacker can exploit CVE-2018-16335 by convincing a victim to open a specially-crafted TIFF file.