Executive Summary

Informations
NameCVE-2018-5784First vendor Publication2018-01-19
VendorCveLast vendor Modification2019-04-22

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Cvss Base Score4.3Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityMedium
Cvss Expoit Score8.6AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5784

CWE : Common Weakness Enumeration

%idName
100 %CWE-400Uncontrolled Resource Consumption ('Resource Exhaustion')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1
Os3
Os3

Nessus® Vulnerability Scanner

DateDescription
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-7a0f7f5768.nasl - Type : ACT_GATHER_INFO
2018-12-01Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4349.nasl - Type : ACT_GATHER_INFO
2018-07-24Name : The remote PhotonOS host is missing multiple security updates.
File : PhotonOS_PHSA-2018-2_0-0039.nasl - Type : ACT_GATHER_INFO
2018-07-03Name : The remote Debian host is missing a security update.
File : debian_DLA-1411.nasl - Type : ACT_GATHER_INFO
2018-06-05Name : The remote Debian host is missing a security update.
File : debian_DLA-1391.nasl - Type : ACT_GATHER_INFO
2018-03-29Name : The remote Fedora host is missing a security update.
File : fedora_2018-e6a51e99a4.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

SourceUrl
CONFIRM https://gitlab.com/libtiff/libtiff/commit/473851d211cf8805a161820337ca74cc961...
DEBIAN https://www.debian.org/security/2018/dsa-4349
MISC http://bugzilla.maptools.org/show_bug.cgi?id=2772
MLIST https://lists.debian.org/debian-lts-announce/2018/05/msg00022.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00002.html
UBUNTU https://usn.ubuntu.com/3602-1/
https://usn.ubuntu.com/3606-1/

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
DateInformations
2019-04-22 21:19:17
  • Multiple Updates
2019-04-20 00:19:09
  • Multiple Updates
2019-03-08 21:19:50
  • Multiple Updates
2018-12-01 17:19:02
  • Multiple Updates
2018-07-04 09:19:48
  • Multiple Updates
2018-06-02 09:18:30
  • Multiple Updates
2018-03-28 12:09:08
  • Multiple Updates
2018-03-22 09:19:27
  • Multiple Updates
2018-02-02 21:20:48
  • Multiple Updates
2018-01-19 13:23:08
  • First insertion