CVE-2018-17000: Null Pointer Dereference
A NULL pointer dereference in the function TIFFmemcmp at tifunix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp.
Other sources
LibTIFF is vulnerable to a denial of service, caused by a NULL pointer dereference in the TIFFmemcmp function in tifunix.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.0.8-2+deb9u5Fixed in 4.0.10-4 - Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1 - Compensating control
Do not open or process untrusted or specially-crafted TIFF files; avoid running LibTIFF's tiffcp on attacker-supplied files to prevent triggering the NULL pointer dereference denial-of-service.
- Operational
If tiffcp (from LibTIFF) was used to process untrusted TIFF files, re-check and restart the processing workflow after blocking access to the malicious inputs.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17000?
CVE-2018-17000 is classified as a denial-of-service vulnerability.
How do I fix CVE-2018-17000?
To fix CVE-2018-17000, upgrade to LibTIFF version 4.0.10 or any higher version available.
What does CVE-2018-17000 affect?
CVE-2018-17000 affects LibTIFF versions up to 4.0.9, specifically impacting TIFF file processing.
Can CVE-2018-17000 be exploited remotely?
Yes, CVE-2018-17000 can be exploited remotely through crafted TIFF files.
What software is vulnerable to CVE-2018-17000?
LibTIFF versions 4.0.9 and lower, as well as certain versions of IBM Cognos Analytics, are vulnerable to CVE-2018-17000.