CVE-2018-17795

unknown
Published — · Modified —
CVSS v3
VIR risk

Description

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.0.9-2
debian debianbullseyefixed4.0.9-2
debian debianforkyfixed4.0.9-2
debian debiansidfixed4.0.9-2
debian debiantrixiefixed4.0.9-2

References

💬 Discuss CVE-2018-17795 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.