Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16232

Опубликовано: 01 нояб. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue

Отчет

Exploitation of this vulnerability requires that an attacker can cause LibTIFF to process a specially crafted malicious file. This is only possible if a system allows untrusted users to submit images, or alternatively, if a user unknowingly takes an action to process a malicious image. Additionally, successful exploitation will result only in a Denial-of-Service (DoS) to the service or process that incorporates LibTIFF. For those reasons, Red Hat's analysis indicates the overall security impact of this flaw is Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 6libtiffWill not fix
Red Hat Enterprise Linux 7compat-libtiff3Will not fix
Red Hat Enterprise Linux 7libtiffWill not fix
Red Hat Enterprise Linux 9libtiffAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1516189libtiff: Memory leaks in tif_open.c, tif_lzw.c, and tif_aux.c

EPSS

Процентиль: 92%
0.05367
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue

CVSS3: 7.5
nvd
больше 7 лет назад

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue

CVSS3: 7.5
debian
больше 7 лет назад

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow at ...

CVSS3: 7.5
github
больше 4 лет назад

** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue.

suse-cvrf
больше 8 лет назад

Security update for tiff

EPSS

Процентиль: 92%
0.05367
Низкий

3.3 Low

CVSS3