PT-2017-4260 · None+5 · Libtiff+5

Published

2017-06-26

·

Updated

2022-12-06

·

CVE-2017-9937

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.8
Description The issue is related to a memory malloc failure in the tif jbig.c component, which can be exploited by a crafted TIFF document, leading to a remote denial of service attack. It is also associated with a buffer overflow in the JBIG1 data compression standard for JBIG-KIT image handling, allowing a remote attacker to cause a service disruption.
Recommendations For LibTIFF version 4.0.8, consider updating to a newer version that addresses the memory malloc failure in tif jbig.c to prevent remote denial of service attacks. As a temporary workaround, restrict the handling of crafted TIFF documents to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1628
AZL-44508
BDU:2023-07608
CVE-2017-9937
ECHO-9D38-6B00-6FE7
MGASA-2022-0449
USN-5742-1

Affected Products

Alt Linux
Astra Linux
Debian
Libtiff
Linuxmint
Ubuntu