Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9404

Опубликовано: 02 июн. 2017
Источник: debian
EPSS Низкий

Описание

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.8-1package
tifffixed4.0.3-12.3+deb8u4jessiepackage
tiff3removedpackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2688

  • Fixed by: https://github.com/vadz/libtiff/commit/2ea32f7372b65c24b2816f11c04bf59b5090d05b

  • Possibly sensible to add the other memory leaks fixes in OJPEGReadHeaderInfoSecTables

  • method from tif_ojpeg.c, i.e.:

  • https://github.com/vadz/libtiff/commit/e9bd1b06fe25219cf0873fca70e46f01843fd9f4

  • https://github.com/vadz/libtiff/commit/8283e4d1b7e53340684d12932880cbcbaf23a8c1

  • Reproducing the issue itself is "covered" after fixing https://github.com/vadz/libtiff/commit/5ed9fea523316c2f5cec4d393e4d5d671c2dbc33

  • To verify 2ea32f7372b65c24b2816f11c04bf59b5090d05b fixes the issue build src:tiff

  • with ASAN with 5ed9fea523316c2f5cec4d393e4d5d671c2dbc33 reverted. Before the

  • 2ea32f7372b65c24b2816f11c04bf59b5090d05b commit the Direct leak of 73 byte

  • with backtrace following the methods in http://bugzilla.maptools.org/show_bug.cgi?id=2688

  • is shown.

EPSS

Процентиль: 76%
0.00962
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
redhat
почти 9 лет назад

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
nvd
больше 8 лет назад

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
github
больше 3 лет назад

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

suse-cvrf
больше 8 лет назад

Security update for tiff

EPSS

Процентиль: 76%
0.00962
Низкий