First published: Sun Sep 16 2018(Updated: )
An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
debian/tiff | 4.2.0-1+deb11u5 4.2.0-1+deb11u6 4.5.0-6+deb12u2 4.5.0-6+deb12u1 4.5.1+git230720-5 | |
Debian | =8.0 | |
Debian | =9.0 | |
libtiff | =4.0.9 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17101 has a severity rating that may lead to application crashes or potential denial of service.
To fix CVE-2018-17101, update to the patched versions of LibTIFF as indicated in the respective vendor advisories.
CVE-2018-17101 affects LibTIFF version 4.0.9.
Yes, CVE-2018-17101 can be exploited via crafted image files which may lead to application crashes.
Affected software includes IBM Cognos Analytics versions up to 12.0.3 and 11.2.4 FP4, as well as specific versions of the Debian tiff package.