CVE-2017-9815
Published: 22 June 2017
In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via a crafted file.
Notes
Author | Note |
---|---|
seth-arnold |
If this actually leaks only the 8 bytes shown in the bug then this cve should be rejected. I'm marking it 'low' rather than 'negligible' just so that we eventually return to the bug and see the results. |
mdeslaur |
same commit as CVE-2017-9403 this will not be fixed in precise/esm |
Priority
Status
Package | Release | Status |
---|---|---|
tiff
Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(4.0.8-1)
|
trusty |
Released
(4.0.3-7ubuntu0.8)
|
|
upstream |
Released
(4.0.8-1)
|
|
xenial |
Released
(4.0.6-1ubuntu0.3)
|
|
yakkety |
Ignored
(end of life)
|
|
zesty |
Ignored
(end of life)
|
|
Patches:
upstream: https://github.com/vadz/libtiff/commit/fb3dc46a2fcf6197ff3b93fc76f0c37fddc0333b |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |