CVE-2018-17101: High severity IBM Cognos Analytics vulnerability
An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an out-of-bounds write in cpTags in tools/tiff2bw.c and tools/pal2rgb.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17101?
CVE-2018-17101 has a severity rating that may lead to application crashes or potential denial of service.
How do I fix CVE-2018-17101?
To fix CVE-2018-17101, update to the patched versions of LibTIFF as indicated in the respective vendor advisories.
Which versions of LibTIFF are affected by CVE-2018-17101?
CVE-2018-17101 affects LibTIFF version 4.0.9.
Can CVE-2018-17101 be exploited remotely?
Yes, CVE-2018-17101 can be exploited via crafted image files which may lead to application crashes.
What software utilizes LibTIFF that is affected by CVE-2018-17101?
Affected software includes IBM Cognos Analytics versions up to 12.0.3 and 11.2.4 FP4, as well as specific versions of the Debian tiff package.