Red Hat Bugzilla – Bug 1609411
CVE-2018-14375 libtiff: NULL dereference in TIFFRGBAImageOK in tif_getimage.c
Last modified: 2018-08-09 04:37:09 EDT
An issue was discovered in LibTIFF 4.0.9. A buffer overflow vulnerability can occur via an invalid or empty tif argument to TIFFRGBAImageOK in tif_getimage.c, and it can be exploited (at a minimum) via the following high-level library API functions: TIFFReadRGBAImage, TIFFRGBAImageOK, and TIFFRGBAImageBegin. References: http://bugzilla.maptools.org/show_bug.cgi?id=2803
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1609414] Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1609413] Affects: fedora-all [bug 1609412]
CVE rejected.