CVE-2018-8905: Buffer Overflow
In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tiflzw.c via a crafted TIFF file, as demonstrated by tiff2ps.
Other sources
LibTIFF since version 3.9.0 is vulnerable to a heap-based buffer overflow in the tiflzw.c:LZWDecodeCompat() function. An attacker could exploit this to cause a denial of service via crafted TIF file.
Upstream Issue: http://bugzilla.maptools.org/showbug.cgi?id=2780
Additional References: https://github.com/halfbitteam/POCs/tree/master/libtiff-4.08tiff2psheapoverflow
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.2-1 - Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Fixed in 4.0.9
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8905?
CVE-2018-8905 is classified as a critical vulnerability due to the potential for a heap-based buffer overflow.
How do I fix CVE-2018-8905?
To resolve CVE-2018-8905, upgrade to LibTIFF version 4.2.0-1+deb11u5 or later.
What software is affected by CVE-2018-8905?
CVE-2018-8905 affects multiple versions of LibTIFF, including version 4.0.9 and versions up to 4.5.1.
Can CVE-2018-8905 be exploited remotely?
Yes, CVE-2018-8905 can be exploited remotely by sending a maliciously crafted TIFF file to the target system.
Is my system safe if it runs a version later than LibTIFF 4.2.0?
Yes, systems running LibTIFF version 4.2.0 or later are not vulnerable to CVE-2018-8905.