Vulnerability Description
In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
CVSS Score
6.5
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libtiff | Libtiff | 4.0.9 |
Related Weaknesses (CWE)
References
- http://bugzilla.maptools.org/show_bug.cgi?id=2770ExploitIssue TrackingPatch
- http://www.securityfocus.com/bid/102345Third Party AdvisoryVDB Entry
- https://gitlab.com/libtiff/libtiff/commit/c6f41df7b581402dfba3c19a1e3df4454c551aPatch
- https://lists.debian.org/debian-lts-announce/2018/01/msg00033.html
- https://lists.debian.org/debian-lts-announce/2018/01/msg00034.html
- https://usn.ubuntu.com/3602-1/
- https://usn.ubuntu.com/3606-1/
- https://www.debian.org/security/2018/dsa-4100
- http://bugzilla.maptools.org/show_bug.cgi?id=2770ExploitIssue TrackingPatch
- http://www.securityfocus.com/bid/102345Third Party AdvisoryVDB Entry
- https://gitlab.com/libtiff/libtiff/commit/c6f41df7b581402dfba3c19a1e3df4454c551aPatch
- https://lists.debian.org/debian-lts-announce/2018/01/msg00033.html
- https://lists.debian.org/debian-lts-announce/2018/01/msg00034.html
- https://usn.ubuntu.com/3602-1/
- https://usn.ubuntu.com/3606-1/
FAQ
What is CVE-2017-18013?
CVE-2017-18013 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
How severe is CVE-2017-18013?
CVE-2017-18013 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18013?
Check the references section above for vendor advisories and patch information. Affected products include: Libtiff Libtiff.