Assertion failure in LibTIFF - CVE-2017-13726

 

Assertion failure in LibTIFF - CVE-2017-13726

Published: June 28, 2018 / Updated: June 29, 2018


Vulnerability identifier: #VU13514
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13726
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition.

The vulnerability exists due to a reachable assertion abort in the function TIFFWriteDirectorySec(), related to tif_dirwrite.c and a SubIFD tag when processing malicious input. A remote attacker can send specially crafted input, trigger assertion failure and cause the service to crash.


Affected software

LibTIFF
Amazon Linux AMI
tiff (Debian package)
openSUSE Leap

How to mitigate CVE-2017-13726

Install update from vendor's website.

tiff (Debian package) - update to 4.0.8-2+deb9u2

External References

Related Security Bulletins