PublicDateAtUSN: 2018-11-12 Candidate: CVE-2018-19210 PublicDate: 2018-11-12 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19210 https://ubuntu.com/security/notices/USN-3906-1 Description: In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset. Ubuntu-Description: Notes: Bugs: http://bugzilla.maptools.org/show_bug.cgi?id=2820 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913675 Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_tiff: other: https://gitlab.com/libtiff/libtiff/merge_requests/47 upstream: https://gitlab.com/libtiff/libtiff/commit/d0a842c5dbad2609aed43c701a12ed12461d3405 upstream: https://gitlab.com/libtiff/libtiff/commit/38ede78b13810ff0fa8e61f86ef9aa0ab2964668 upstream_tiff: released (4.0.10-4) precise/esm_tiff: ignored (end of ESM support, was needed) trusty_tiff: released (4.0.3-7ubuntu0.11) trusty/esm_tiff: released (4.0.3-7ubuntu0.11) xenial_tiff: released (4.0.6-1ubuntu0.6) esm-infra/xenial_tiff: released (4.0.6-1ubuntu0.6) bionic_tiff: released (4.0.9-5ubuntu0.2) cosmic_tiff: released (4.0.9-6ubuntu0.2) disco_tiff: not-affected (4.0.10-4) eoan_tiff: not-affected (4.0.10-4) focal_tiff: not-affected (4.0.10-4) groovy_tiff: not-affected (4.0.10-4) hirsute_tiff: not-affected (4.0.10-4) devel_tiff: not-affected (4.0.10-4)