Red Hat Bugzilla – Bug 1631078
CVE-2018-17101 libtiff: Two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c
Last modified: 2018-10-02 06:18:06 EDT
An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. Upstream issue: http://bugzilla.maptools.org/show_bug.cgi?id=2807 Upstream patch: https://gitlab.com/libtiff/libtiff/merge_requests/33/diffs?commit_id=f1b94e8a3ba49febdd3361c0214a1d1149251577
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1631079] Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1631082] Affects: fedora-all [bug 1631080]
Out of bounds write, seems non-exploitable, so mostly crash only.