PT-2019-8042 · None+2 · Libtiff+2

Published

2018-01-12

·

Updated

2026-03-31

·

CVE-2017-16232

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.8
Description The issue allows attackers to cause a denial of service due to memory consumption. It is demonstrated by files such as tif open.c, tif lzw.c, and tif aux.c. However, third parties were unable to reproduce the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

CVE-2017-16232
ECHO-20F5-1D38-DB71
OPENSUSE-SU-2018_0097-1
OPENSUSE-SU-2024:11461-1
SUSE-SU-2018:0073-1

Affected Products

Debian
Libtiff
Suse