CVE Vulnerabilities

CVE-2019-7663

Published: Feb 09, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

Affected Software

NameVendorStart VersionEnd Version
LibtiffLibtiff4.0.10 (including)4.0.10 (including)
GdalUbuntuesm-apps/xenial*
GdalUbuntuesm-infra-legacy/trusty*
GdalUbuntutrusty*
GdalUbuntutrusty/esm*
GdalUbuntuxenial*
Openjpeg2Ubuntucosmic*
Openjpeg2Ubuntuupstream*
Qt4-x11Ubuntucosmic*
Qt4-x11Ubuntutrusty*
Qtimageformats-opensource-srcUbuntubionic*
Qtimageformats-opensource-srcUbuntucosmic*
Qtimageformats-opensource-srcUbuntudisco*
Qtimageformats-opensource-srcUbuntueoan*
Qtimageformats-opensource-srcUbuntufocal*
Qtimageformats-opensource-srcUbuntugroovy*
Qtimageformats-opensource-srcUbuntuhirsute*
Qtimageformats-opensource-srcUbuntuimpish*
Qtimageformats-opensource-srcUbuntukinetic*
Qtimageformats-opensource-srcUbuntulunar*
Qtimageformats-opensource-srcUbuntumantic*
Qtimageformats-opensource-srcUbuntuoracular*
Qtimageformats-opensource-srcUbuntuplucky*
Qtimageformats-opensource-srcUbuntutrusty*
Qtimageformats-opensource-srcUbuntuxenial*
Qtwebengine-opensource-srcUbuntubionic*
Qtwebengine-opensource-srcUbuntucosmic*
Qtwebengine-opensource-srcUbuntudisco*
Qtwebengine-opensource-srcUbuntueoan*
Qtwebengine-opensource-srcUbuntufocal*
Qtwebengine-opensource-srcUbuntugroovy*
Qtwebengine-opensource-srcUbuntuhirsute*
Qtwebengine-opensource-srcUbuntuimpish*
Qtwebengine-opensource-srcUbuntukinetic*
Qtwebengine-opensource-srcUbuntulunar*
Qtwebengine-opensource-srcUbuntumantic*
Qtwebengine-opensource-srcUbuntuoracular*
Qtwebengine-opensource-srcUbuntuplucky*
TexmakerUbuntubionic*
TexmakerUbuntucosmic*
TexmakerUbuntudisco*
TexmakerUbuntueoan*
TexmakerUbuntufocal*
TexmakerUbuntugroovy*
TexmakerUbuntuhirsute*
TexmakerUbuntuimpish*
TexmakerUbuntukinetic*
TexmakerUbuntulunar*
TexmakerUbuntumantic*
TexmakerUbuntuoracular*
TexmakerUbuntuplucky*
TexmakerUbuntutrusty*
TexmakerUbuntuxenial*
TiffUbuntubionic*
TiffUbuntucosmic*
TiffUbuntuesm-infra-legacy/trusty*
TiffUbuntuesm-infra/bionic*
TiffUbuntuesm-infra/xenial*
TiffUbuntutrusty*
TiffUbuntutrusty/esm*
TiffUbuntuupstream*
TiffUbuntuxenial*

References