SB2019082831 - Integer overflow in tiff (Alpine package)
Published: August 28, 2019 Updated: May 21, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2019-14973)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks.
The vulnerability exists due to integer overflow in the "_TIFFCheckMalloc" and "_TIFFCheckRealloc" functions in the "tif_aux.c" file. A remote attacker can trick a victim to open a specially crafted file that contains crafted TIFF images, trigger integer overflow and crash the target application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=264df00ff86995f0cec1bf60488ce863f57304d9
- https://git.alpinelinux.org/aports/commit/?id=67b27f44d268a8b0bec9de6a17edcd195d4eef71
- https://git.alpinelinux.org/aports/commit/?id=928d37312121806dd7635626fa0d21b333bb4eb0
- https://git.alpinelinux.org/aports/commit/?id=cbc7159a44308ba1aa3edc3d95c9178790e9a72f
- https://git.alpinelinux.org/aports/commit/?id=de0584e234c2dad9d4247ee7de308a95fe2b42ac