First published: Fri Oct 26 2018(Updated: )
An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/tiff | 4.2.0-1+deb11u5 4.2.0-1+deb11u6 4.5.0-6+deb12u2 4.5.0-6+deb12u1 4.5.1+git230720-5 | |
tiff | =4.0.9 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18661 has a medium severity due to the potential for a denial of service through NULL pointer dereference.
To mitigate CVE-2018-18661, upgrade to LibTIFF version 4.2.0-1+deb11u5 or later for Debian systems.
CVE-2018-18661 affects LibTIFF version 4.0.9 as well as various versions of the tiff package in Debian and Ubuntu Linux.
CVE-2018-18661 is a NULL pointer dereference vulnerability found in the LZWDecode function of LibTIFF.
CVE-2018-18661 is primarily a denial of service vulnerability and does not directly lead to remote code execution or system compromise.