CVE-2018-12900

NameCVE-2018-12900
DescriptionHeap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2009-1, DSA-4670-1
NVD severitymedium
Debian Bugs902718

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tiff (PTS)stretch4.0.8-2+deb9u5fixed
stretch (security)4.0.8-2+deb9u6fixed
buster, buster (security)4.1.0+git191117-2~deb10u2fixed
bookworm, bullseye4.2.0-1fixed
sid4.3.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tiffsourcejessie4.0.3-12.3+deb8u10DLA-2009-1
tiffsourcestretch4.0.8-2+deb9u5DSA-4670-1
tiffsource(unstable)4.0.10-4902718

Notes

http://bugzilla.maptools.org/show_bug.cgi?id=2798
https://gitlab.com/libtiff/libtiff/merge_requests/60
https://gitlab.com/libtiff/libtiff/commit/27124e9148b2056d0e0bf4033b4924d5d2a38d01

Search for package or bug name: Reporting problems