PT-2017-17826 · None+2 · Libtiff+2
Agostino Sarubbo
·
Published
2017-04-09
·
Updated
2024-06-15
·
CVE-2017-7595
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibTIFF version 4.0.7
Description
The issue allows remote attackers to cause a denial of service, resulting in a divide-by-zero error and application crash, via a crafted image. This is due to a problem in the JPEGSetupEncode function in tiff jpeg.c.
Recommendations
For LibTIFF version 4.0.7, consider avoiding the use of the JPEGSetupEncode function in tiff jpeg.c until a patch is available. As a temporary workaround, restrict the processing of crafted images to minimize the risk of exploitation.
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libtiff
Suse
Ubuntu