Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 667638 (CVE-2018-17795) - <media-libs/tiff-4.0.9-r4: heap based buffer overflow vulnerability
Summary: <media-libs/tiff-4.0.9-r4: heap based buffer overflow vulnerability
Status: RESOLVED FIXED
Alias: CVE-2018-17795
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://bugzilla.maptools.org/show_bug...
Whiteboard: A3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-10-03 08:02 UTC by D'juan McDonald (domhnall)
Modified: 2019-03-26 20:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2018-10-03 08:02:33 UTC
LibTIFF is prone to a heap-based buffer-overflow vulnerability.

An attacker can exploit this issue to cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.

LibTIFF 4.0.9 is vulnerable; other versions may also be affected.

@maintainer(s): currently, bug is not reproducible by upstream. See $URL for more details.

Gentoo Security Padawan
(domhnall)
Comment 1 D'juan McDonald (domhnall) 2018-11-16 00:24:04 UTC
Correction, the actual text is: 

"The remote attackers can still cause a denial of service via various
buffer-overflow. Fortunately, we cannot reproduce this bug _after_:

commit 3dd8f6a357981a4090f126ab9025056c938b6940."

my mistake. 

@maintainer(s): this patch is in current 4.0.9-r4 via https://gitlab.com/libtiff/libtiff/tree/3dd8f6a357981a4090f126ab9025056c938b6940, that fixes CVE-2017-9935 with the -fix-incorrect-type patch. This issue can be closed.

@security, ping. free CVE here for tracking.

Gentoo Security Padawan
(domhnall/mbailey_j)
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2019-03-10 05:54:07 UTC
Maintainer(s), please advise if you are ready for stabilization or call for stabilization yourself.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2019-03-24 21:20:15 UTC
@graphics - this is an A3 vulnerability (10 days to fix), can you please take a look at this, as all of this has been in Neverland for a while.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2019-03-26 18:50:18 UTC
Code is present in 3.x release.  So it is vulnerable.
Comment 5 Aaron Bauman (RETIRED) gentoo-dev 2019-03-26 20:28:47 UTC
Tree is clean