Candidate: CVE-2018-10801 PublicDate: 2018-05-08 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10801 Description: TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff. Ubuntu-Description: Notes: mdeslaur> upstream removed the bmp2tiff utility in 4.0.7 mdeslaur> this is a memory leak in a command-line tool, we will not be mdeslaur> fixing this issue in precise, trusty or xenial. Marking as mdeslaur> ignored. Bugs: http://bugzilla.maptools.org/show_bug.cgi?id=2790 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_tiff: upstream_tiff: needs-triage precise/esm_tiff: ignored trusty_tiff: ignored trusty/esm_tiff: ignored xenial_tiff: ignored esm-infra/xenial_tiff: ignored artful_tiff: not-affected (4.0.8-5ubuntu0.1) bionic_tiff: not-affected (4.0.9-5) cosmic_tiff: not-affected (4.0.9-5) devel_tiff: not-affected (4.0.9-5)