CVE-2019-14973: Integer Overflow
TIFFCheckMalloc and TIFFCheckRealloc in tifaux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an iInteger overflow in the TIFFCheckMalloc and TIFFCheckRealloc in tifaux.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-14973.
What is the severity of CVE-2019-14973?
The severity of CVE-2019-14973 is high with a severity value of 7.
How does CVE-2019-14973 affect LibTIFF?
CVE-2019-14973 affects LibTIFF versions up to and including 4.0.10.
How can I fix CVE-2019-14973 in LibTIFF?
To fix CVE-2019-14973 in LibTIFF, update to version 4.0.9-5ubuntu0.3 or later.
Where can I find more information about CVE-2019-14973?
You can find more information about CVE-2019-14973 at the following references: [link1], [link2], [link3].