ID:1261 - Exploit for Denial of service in LibTIFF - CVE-2017-10688

 
Main Vulnerability Database Exploits ID:1261 - Exploit for Denial of service in LibTIFF - CVE-2017-10688

ID:1261 - Exploit for Denial of service in LibTIFF - CVE-2017-10688

Published: March 18, 2020


Vulnerability identifier: #VU7407
Vulnerability risk: Low
CVE-ID: CVE-2017-10688
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
LibTIFF

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to cause DoS condition.

The weakness exits due to assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A remote attacker can send specially crafted TIFF file and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Update to version 4.0.8-3.