Out-of-bounds read in Netpbm and Fedora - CVE-2017-5849

 

Out-of-bounds read in Netpbm and Fedora - CVE-2017-5849

Published: March 15, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39452
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5849
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.


Affected software

Netpbm
Fedora
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Basesystem Module
Desktop Applications Module
openSUSE Leap
libnetpbm-devel
libnetpbm11-debuginfo-32bit
libnetpbm11-32bit
netpbm-debuginfo
libnetpbm11-debuginfo
netpbm-debugsource
libnetpbm11
netpbm
libnetpbm11-32bit-debuginfo
netpbm-vulnerable
netpbm-vulnerable-debuginfo

How to mitigate CVE-2017-5849

Install update from vendor's website.

libnetpbm-devel - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
libnetpbm11-debuginfo-32bit - update to 10.66.3-8.10.1
libnetpbm11-32bit - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
netpbm-debuginfo - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
libnetpbm11-debuginfo - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
netpbm-debugsource - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
libnetpbm11 - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
netpbm - addressed in versions 10.66.3-8.10.1, 10.80.1-150000.3.14.1
libnetpbm11-32bit-debuginfo - update to 10.80.1-150000.3.14.1
netpbm-vulnerable - update to 10.80.1-150000.3.14.1
netpbm-vulnerable-debuginfo - update to 10.80.1-150000.3.14.1

External References

Related Security Bulletins