PT-2017-19298 · Libtiff+3 · Libtiff+3
Owl337
·
Published
2017-06-26
·
Updated
2024-06-15
·
CVE-2017-9935
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibTIFF version 4.0.8
Description
The issue is related to a heap-based buffer overflow in the
t2p write pdf function. This overflow could lead to various damages, including out-of-bounds read, invalid free, memory corruption, or double free. It is possible that a crafted TIFF document could cause arbitrary code execution.Recommendations
For LibTIFF version 4.0.8, consider updating to a newer version that contains a fix for this issue. As a temporary workaround, restrict the use of the
t2p write pdf function in tools/tiff2pdf.c to minimize the risk of exploitation. Avoid processing crafted TIFF documents until the issue is resolved.Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libtiff
Suse
Ubuntu