Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-9147

Published: 22 May 2017

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

Notes

AuthorNote
ratliff
reproducer errors out on precise, trusty rather than crashing
mdeslaur
same problem as CVE-2015-7554

Priority

Negligible

CVSS 3 base score: 6.5

Status

Package Release Status
tiff
Launchpad, Ubuntu, Debian
artful Not vulnerable
(4.0.8-4)
precise Not vulnerable

trusty Not vulnerable

upstream
Released (4.0.8-2)
xenial
Released (4.0.6-1ubuntu0.4)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)