CVE-2018-19210 PUBLISHED

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

EPSS 4.91% · 89.5th percentile

Risk Scores

EPSS Score
4.91%
89.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStiff0, 4.0.6-1ubuntu0.5, 4.0.6-1ubuntu0.4
Ubuntu:18.04:LTStiff4.0.9-5ubuntu0.1, 0, 4.0.8-5
Ubuntu:14.04:LTStiff4.0.3-7, 4.0.3-6ubuntu1, 4.0.3-6

Timeline

References

Open in Interactive Console →