LibTIFF is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to obtain sensitive information or cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.
LibTIFF 4.0.9 is vulnerable; other versions may also be affected.
Information
Redhat Enterprise Linux 6
Redhat Enterprise Linux 5
LibTIFF LibTIFF 4.0.9
Exploit
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
References:
- LibTIFF Homepage (LibTIFF)
- Bug 1529524 - (CVE-2017-17942) CVE-2017-17942 libtiff: Heap-based buffer overfl (Redhat)
- Bug 2767 - A heap-buffer-overflow in libtiff 4.0.8. (maptools.org)
- CVE-2017-17942 (Redhat)