An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libtiff | Libtiff | 4.0.10 (including) | 4.0.10 (including) |
| Gdal | Ubuntu | esm-apps/xenial | * |
| Gdal | Ubuntu | esm-infra-legacy/trusty | * |
| Gdal | Ubuntu | trusty | * |
| Gdal | Ubuntu | trusty/esm | * |
| Gdal | Ubuntu | xenial | * |
| Openjpeg2 | Ubuntu | cosmic | * |
| Openjpeg2 | Ubuntu | upstream | * |
| Qt4-x11 | Ubuntu | cosmic | * |
| Qt4-x11 | Ubuntu | trusty | * |
| Qtimageformats-opensource-src | Ubuntu | bionic | * |
| Qtimageformats-opensource-src | Ubuntu | cosmic | * |
| Qtimageformats-opensource-src | Ubuntu | disco | * |
| Qtimageformats-opensource-src | Ubuntu | eoan | * |
| Qtimageformats-opensource-src | Ubuntu | focal | * |
| Qtimageformats-opensource-src | Ubuntu | groovy | * |
| Qtimageformats-opensource-src | Ubuntu | hirsute | * |
| Qtimageformats-opensource-src | Ubuntu | impish | * |
| Qtimageformats-opensource-src | Ubuntu | kinetic | * |
| Qtimageformats-opensource-src | Ubuntu | lunar | * |
| Qtimageformats-opensource-src | Ubuntu | mantic | * |
| Qtimageformats-opensource-src | Ubuntu | oracular | * |
| Qtimageformats-opensource-src | Ubuntu | trusty | * |
| Qtimageformats-opensource-src | Ubuntu | xenial | * |
| Qtwebengine-opensource-src | Ubuntu | bionic | * |
| Qtwebengine-opensource-src | Ubuntu | cosmic | * |
| Qtwebengine-opensource-src | Ubuntu | disco | * |
| Qtwebengine-opensource-src | Ubuntu | eoan | * |
| Qtwebengine-opensource-src | Ubuntu | focal | * |
| Qtwebengine-opensource-src | Ubuntu | groovy | * |
| Qtwebengine-opensource-src | Ubuntu | hirsute | * |
| Qtwebengine-opensource-src | Ubuntu | impish | * |
| Qtwebengine-opensource-src | Ubuntu | kinetic | * |
| Qtwebengine-opensource-src | Ubuntu | lunar | * |
| Qtwebengine-opensource-src | Ubuntu | mantic | * |
| Qtwebengine-opensource-src | Ubuntu | oracular | * |
| Texmaker | Ubuntu | bionic | * |
| Texmaker | Ubuntu | cosmic | * |
| Texmaker | Ubuntu | disco | * |
| Texmaker | Ubuntu | eoan | * |
| Texmaker | Ubuntu | focal | * |
| Texmaker | Ubuntu | groovy | * |
| Texmaker | Ubuntu | hirsute | * |
| Texmaker | Ubuntu | impish | * |
| Texmaker | Ubuntu | kinetic | * |
| Texmaker | Ubuntu | lunar | * |
| Texmaker | Ubuntu | mantic | * |
| Texmaker | Ubuntu | oracular | * |
| Texmaker | Ubuntu | trusty | * |
| Texmaker | Ubuntu | xenial | * |
| Tiff | Ubuntu | bionic | * |
| Tiff | Ubuntu | cosmic | * |
| Tiff | Ubuntu | esm-infra-legacy/trusty | * |
| Tiff | Ubuntu | esm-infra/bionic | * |
| Tiff | Ubuntu | esm-infra/xenial | * |
| Tiff | Ubuntu | trusty | * |
| Tiff | Ubuntu | trusty/esm | * |
| Tiff | Ubuntu | upstream | * |
| Tiff | Ubuntu | xenial | * |