CVE-2018-5784: Medium severity IBM Cognos Analytics vulnerability
In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tifdir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw in the TIFFSetDirectory function of tifdir.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1 - Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Fixed in 4.0.9
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5784?
CVE-2018-5784 has been classified as a denial of service vulnerability due to uncontrolled resource consumption.
How do I fix CVE-2018-5784?
To mitigate CVE-2018-5784, you should apply the patches provided by IBM for Cognos Analytics or update the TIFF package on Debian.
Which versions of IBM Cognos Analytics are affected by CVE-2018-5784?
CVE-2018-5784 affects IBM Cognos Analytics versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.3.
Which versions of the TIFF package are vulnerable to CVE-2018-5784?
The TIFF package version 4.0.9 is vulnerable to CVE-2018-5784.
Can remote attackers exploit CVE-2018-5784?
Yes, remote attackers can leverage CVE-2018-5784 to cause denial of service by sending crafted TIFF files.