CVE-2017-18013NULL Pointer Dereference in Libtiff

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 49.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 1
Latest updateMay 14

Description

In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.9
debiandebian/tiff< tiff 4.0.9-3 (bookworm)+1

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-cp7r-wf78-8x92: In LibTIFF 42022-05-14
GHSA
GHSA-43j5-gmq7-54cr: A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print2022-05-13
OSV
CVE-2018-7456: A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print2018-02-24
OSV
CVE-2017-18013: In LibTIFF 42018-01-01

📋Vendor Advisories

6
Ubuntu
LibTIFF vulnerabilities2018-03-26
Ubuntu
LibTIFF vulnerabilities2018-03-20
Red Hat
libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes a denial of service2018-02-24
Debian
CVE-2018-7456: tiff - A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_prin...2018
Red Hat
libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes crash2017-12-29

💬Community

3
Bugzilla
CVE-2018-7456 libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes a denial of service2018-03-15
Bugzilla
CVE-2017-18013 libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes crash2018-01-03
Bugzilla
CVE-2017-18013 libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes crash [fedora-all]2018-01-03