High severity8.8NVD Advisory· Published Oct 22, 2018· Updated Jun 17, 2026
CVE-2018-18557
CVE-2018-18557
Description
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode out-of-bounds write.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
203.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9+ 1 more
- (no CPE)range: 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9
- cpe:2.3:a:libtiff:libtiff:4.0.9:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- osv-coords12 versionspkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/opensuse/tiff&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4
< 4.0.9-44.27.1+ 11 more
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.0.9-5.17.1
- (no CPE)range: < 4.0.9-5.17.1
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.3.0-1.3
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.0.9-44.27.1
- (no CPE)range: < 4.0.9-5.17.1
- (no CPE)range: < 4.0.9-44.27.1
Patches
Vulnerability mechanics
References
10- www.exploit-db.com/exploits/45694/nvdExploitThird Party AdvisoryVDB Entry
- gitlab.com/libtiff/libtiff/merge_requests/38nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/10/msg00019.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/3864-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4349nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2053nvd
- github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-18557nvd
- gitlab.com/libtiff/libtiff/commit/681748ec2f5ce88da5f9fa6831e1653e46af8a66nvd
- security.gentoo.org/glsa/201904-15nvd
- usn.ubuntu.com/3906-2/nvd
News mentions
0No linked articles in our index yet.