Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://bugzilla.maptools.org/show_bug.cgi?id=2798 | issue tracking exploit third party advisory |
https://usn.ubuntu.com/3906-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/3906-2/ | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:2053 | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:3419 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html | mailing list |
https://www.debian.org/security/2020/dsa-4670 | vendor advisory |
https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-12900 |