CVE-2017-12944Allocation of Resources Without Limits or Throttling in Libtiff

Severity
7.5HIGHNVD
EPSS
0.7%
top 27.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 18
Latest updateMay 13

Description

The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.8
debiandebian/tiff< tiff 4.0.8-6 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-r6g8-rrwj-46q5: The TIFFReadDirEntryArray function in tif_read2022-05-13
OSV
CVE-2017-12944: The TIFFReadDirEntryArray function in tif_read2017-08-18

📋Vendor Advisories

4
Ubuntu
LibTIFF vulnerabilities2018-03-26
Ubuntu
LibTIFF vulnerabilities2018-03-20
Red Hat
libtiff: Mishandled memory allocation for short files in the TIFFReadDirEntryArray function2017-08-06
Debian
CVE-2017-12944: tiff - The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles mem...2017

💬Community

4
Bugzilla
CVE-2017-12944 libtiff: Mishandled memory allocation for short files in the TIFFReadDirEntryArray function2017-08-31
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 mingw-libtiff: various flaws [fedora-all]2017-07-24
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 mingw-libtiff: various flaws [epel-7]2017-07-24
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 libtiff: various flaws [fedora-all]2017-07-24