CVE-2018-5360: High severity LibTIFF libtiff vulnerability
Published Jan 14, 2018
·Updated
LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.
Affected Software
2 affected components
LibTIFF libtiff<4.0.6
GraphicsMagick Graphicsmagick=1.3.27
Remediation
Event History
Jan 14, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-5360.
2
What is the severity of CVE-2018-5360?
The severity of CVE-2018-5360 is high with a score of 8.8.
3
What software is affected by CVE-2018-5360?
LibTIFF versions before 4.0.6 and GraphicsMagick version 1.3.27 are affected.
4
What is the CWE number associated with CVE-2018-5360?
The CWE number associated with CVE-2018-5360 is 125.
5
How do I fix CVE-2018-5360?
To fix CVE-2018-5360, update LibTIFF to version 4.0.6 or later, and GraphicsMagick to version 1.3.28 or later.