LibTIFF CVE-2017-17942 Heap Based Buffer Overflow Vulnerability



LibTIFF is prone to a heap-based buffer-overflow vulnerability.

An attacker can exploit this issue to obtain sensitive information or cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.

LibTIFF 4.0.9 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 102312
Class: Boundary Condition Error
CVE: CVE-2017-17942

Remote: Yes
Local: No
Published: Dec 28 2017 12:00AM
Updated: Dec 28 2017 12:00AM
Credit: The vendor reported this issue.
Vulnerable: Redhat Enterprise Linux 7
Redhat Enterprise Linux 6
+ Trustix Secure Enterprise Linux 2.0
+ Trustix Secure Linux 2.2
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
Redhat Enterprise Linux 5
LibTIFF LibTIFF 4.0.9


Not Vulnerable:

Exploit


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.


Related Posts