Improper input validation in LibTIFF - CVE-2017-11613

 

Improper input validation in LibTIFF - CVE-2017-11613

Published: April 3, 2018


Vulnerability identifier: #VU11494
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11613
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the TIFFOpen function due to improper checking of td_imagelength during the TIFFOpen process. A remote attacker can cause the service to crash.

Affected software

LibTIFF
Arch Linux
Debian Linux
Opensuse
Fedora
tiff (Alpine package)
openSUSE Leap
libtiff
Dynamic System Analysis (DSA) Preboot

How to mitigate CVE-2017-11613

Install update from vendor's website.

tiff (Alpine package) - addressed in versions 4.0.9-r5, 4.0.9-r6
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - addressed in versions 4.0.9-10.fc27, 4.0.9-10.fc28

External References

Related Security Bulletins