Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17973

Опубликовано: 29 дек. 2017
Источник: redhat
CVSS3: 7.5

Описание

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

Отчет

Red Hat engineering was unable to reproduce this issue. Also there was no update from upstream about the ability to validate this bug. As a result there would be no fixes available for this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffNot affected
Red Hat Enterprise Linux 6libtiffNot affected
Red Hat Enterprise Linux 7libtiffNot affected
Red Hat Enterprise Linux 8libtiffNot affected
Red Hat Enterprise Linux 9libtiffNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1530912libtiff: heap-based use after free in tiff2pdf.c:t2p_writeproc

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

CVSS3: 8.8
nvd
больше 8 лет назад

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

CVSS3: 8.8
debian
больше 8 лет назад

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writ ...

CVSS3: 8.8
github
больше 4 лет назад

** DISPUTED ** In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue.

suse-cvrf
больше 8 лет назад

Security update for tiff

7.5 High

CVSS3