UBUNTU-CVE-2018-12900
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12900
UBUNTU-CVE-2018-12900
Summary:
Details: Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
References: https://ubuntu.com/security/CVE-2018-12900, https://ubuntu.com/security/notices/USN-3906-1, https://ubuntu.com/security/notices/USN-3906-2, https://www.cve.org/CVERecord?id=CVE-2018-12900
Affected packages
Package
Name: tiff
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
