PT-2017-16711 · Netpbm+2 · Netpbm+2
Chunibalon
·
Published
2017-03-15
·
Updated
2024-06-15
·
CVE-2017-5849
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
netpbm version 10.47.63
Description
The issue is related to the improper use of the libtiff TIFFRGBAImageGet function by tiffttopnm in netpbm, allowing remote attackers to cause a denial of service through an out-of-bounds read and write via a crafted tiff image file. This is due to the transposing of width and height values.
Recommendations
For netpbm version 10.47.63, consider updating to a newer version that properly handles the libtiff TIFFRGBAImageGet function to prevent out-of-bounds read and write operations. As a temporary workaround, restrict the use of tiffttopnm with untrusted tiff image files to minimize the risk of exploitation.
Exploit
Fix
DoS
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Libtiff
Netpbm