CVE-2018-18557: High severity LibTIFF libtiff vulnerability
Last updated 25 August 2025
Other sources
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tifjbig.c JBIGDecode out-of-bounds write.
— Launchpad
LibTIFF 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tifjbig.c JBIGDecode out-of-bounds write.
Upstream MR:
https://gitlab.com/libtiff/libtiff/mergerequests/38
References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1697
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18557?
CVE-2018-18557 is classified as a critical vulnerability due to its potential for buffer overflow leading to arbitrary code execution.
How do I fix CVE-2018-18557?
To fix CVE-2018-18557, upgrade to versions 4.2.0-1+deb11u5, 4.2.0-1+deb11u6, 4.5.0-6+deb12u2, 4.5.0-6+deb12u1, or 4.5.1+git230720-5 of the libtiff library.
What software is affected by CVE-2018-18557?
CVE-2018-18557 affects multiple versions of libtiff, specifically versions 3.9.3 through 4.0.9 with JBIG enabled.
What are the potential impacts of CVE-2018-18557?
The potential impacts of CVE-2018-18557 include remote code execution and denial-of-service attacks if exploited.
Is CVE-2018-18557 relevant to Debian and Ubuntu users?
Yes, CVE-2018-18557 is relevant to users of Debian Linux 8.0, 9.0, as well as various versions of Ubuntu Linux, as these distributions use libtiff.