Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17095

Опубликовано: 29 нояб. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

A vulnerability was found in LibTIFF, where a heap-based buffer overflow in the pal2rgb function in tools/pal2rgb.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash.

Отчет

This vulnerability is rated as moderate because it allows a remote attacker to trigger a denial of service through a heap-based buffer overflow, exploiting this flaw would crash the application, affecting availability without compromising system integrity. This vulnerability affects the pal2rgb executable which is part of the tools distributed with libtiff upstream, but shipped in libtiff-tools RPM package instead of libtiff package on Red Hat Enterprise Linux distribution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffOut of support scope
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Out of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8libtiffFixedRHSA-2025:465807.05.2025
Red Hat Enterprise Linux 9libtiffFixedRHSA-2023:657507.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1524284libtiff: Heap-based buffer overflow in tools/pal2rgb.c can lead to denial of service

EPSS

Процентиль: 88%
0.03989
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

CVSS3: 8.8
nvd
больше 8 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

CVSS3: 8.8
debian
больше 8 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to ...

rocky
8 месяцев назад

Moderate: libtiff security update

CVSS3: 8.8
github
почти 4 года назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

EPSS

Процентиль: 88%
0.03989
Низкий

7.5 High

CVSS3