ZeroHour

CVE-2018-5784

PoC
CVSS 3.0
6.5 medium
EPSS
3%p86
Published
()
Modified
Description

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

Vendors
libtiffdebiancanonical
Products
libtiff, debian linux, ubuntu linux
Weakness
CWE-400
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.