Buffer overflow in LibTIFF - CVE-2017-16231

 

Buffer overflow in LibTIFF - CVE-2017-16231

Published: March 21, 2019 / Updated: July 28, 2020


Vulnerability identifier: #VU31989
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16231
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

** DISPUTED ** In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used.


Affected software

LibTIFF
tiff (Alpine package)

How to mitigate CVE-2017-16231

Install update from vendor's website.

tiff (Alpine package) - update to 4.0.9-r0

External References

Related Security Bulletins