PT-2017-4260 · None+5 · Libtiff+5
CVE-2017-9937
·
Publicado
2017-06-26
·
Atualizado
2022-12-06
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
LibTIFF version 4.0.8
Description
The issue is related to a memory malloc failure in the tif jbig.c component, which can be exploited by a crafted TIFF document, leading to a remote denial of service attack. It is also associated with a buffer overflow in the JBIG1 data compression standard for JBIG-KIT image handling, allowing a remote attacker to cause a service disruption.
Recommendations
For LibTIFF version 4.0.8, consider updating to a newer version that addresses the memory malloc failure in tif jbig.c to prevent remote denial of service attacks. As a temporary workaround, restrict the handling of crafted TIFF documents to minimize the risk of exploitation.
Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Debian
Libtiff
Linuxmint
Ubuntu