CVE-2019-7663 PUBLISHED

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

EPSS 0.70% · 71.8th percentile

Risk Scores

EPSS Score
0.70%
71.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSgdal1.10.1+dfsg-2, 1.10.1+dfsg-3, 1.10.1+dfsg-3build1
Ubuntu:18.04:LTSqtwebengine-opensource-src5.9.1+dfsg-4ubuntu1, 5.9.2+dfsg-2ubuntu1, 5.9.3+dfsg-0ubuntu1
Ubuntu:22.04:LTStexmaker0, 5.0.3-1build9, 5.0.3-1build8
Ubuntu:16.04:LTStexmaker4.4.1-1.1, 4.4.1-1, 0
Ubuntu:25.10qtimageformats-opensource-src0, 5.15.17-1, 5.15.15-3
Ubuntu:22.04:LTSqtwebengine-opensource-src5.15.8+dfsg-1, 5.15.9+dfsg-1, 5.15.8+dfsg-2
Ubuntu:18.04:LTSqtimageformats-opensource-src5.9.5-0ubuntu1, 5.9.2-2, 5.9.3-1ubuntu1
Ubuntu:20.04:LTSqtimageformats-opensource-src5.12.5-1, 5.12.4-1, 0
Ubuntu:16.04:LTStiff4.0.6-1ubuntu0.4, 4.0.5-1, 4.0.3-12.3ubuntu2
Ubuntu:25.10qtwebengine-opensource-src5.15.18+dfsg-2, 5.15.18+dfsg-2build1, 5.15.19+dfsg-1
Ubuntu:25.10texmaker5.1.3+dfsg-3, 0, 5.1.3+dfsg-3build1
Ubuntu:20.04:LTSqtwebengine-opensource-src5.12.5+dfsg-7build1, 0, 5.12.4+dfsg-1ubuntu1
Ubuntu:18.04:LTStexmaker0, 5.0.2-1build2, 5.0.2-1build1
Ubuntu:24.04:LTStexmaker5.1.3+dfsg-1build6, 5.1.3+dfsg-1build5, 5.1.3+dfsg-1build4
Ubuntu:22.04:LTSqtimageformats-opensource-src0, 5.15.3-1, 5.15.2-2build1
Ubuntu:24.04:LTSqtimageformats-opensource-src5.15.13-1, 5.15.12-1build1, 5.15.12-1
Ubuntu:14.04:LTStiff4.0.3-5ubuntu1, 4.0.3-7ubuntu0.3, 4.0.3-7ubuntu0.2
Ubuntu:16.04:LTSqtimageformats-opensource-src5.5.1-2build1, 5.4.2-2build1, 0
Ubuntu:16.04:LTSgdal0, 1.11.3+dfsg-3build1, 1.11.3+dfsg-3build2
Ubuntu:24.04:LTSqtwebengine-opensource-src5.15.15+dfsg-2ubuntu1, 5.15.16+dfsg-1, 5.15.16+dfsg-1ubuntu2

…and 2 more

Timeline

References

Open in Interactive Console →