ID:1259 - Exploit for Improper input validation in LibTIFF - CVE-2017-9147

 
Main Vulnerability Database Exploits ID:1259 - Exploit for Improper input validation in LibTIFF - CVE-2017-9147

ID:1259 - Exploit for Improper input validation in LibTIFF - CVE-2017-9147

Published: March 18, 2020


Vulnerability identifier: #VU7403
Vulnerability risk: Low
CVE-ID: CVE-2017-9147
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
LibTIFF

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to cause DoS condition.

The weakness exits due to invalid read in the _TIFFVGetField function in tif_dir.c. A remote attacker can send specially crafted TIFF file and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Update to version 4.0.8-3.