CVE-2017-13726Reachable Assertion in Libtiff

CWE-617Reachable Assertion15 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
0.6%
top 29.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 13

Description

There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.9+1
debiandebian/tiff< tiff 4.0.9-6 (bookworm)+1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

🔴Vulnerability Details

4
GHSA
GHSA-v297-429x-xxgh: The TIFFWriteDirectorySec() function in tif_dirwrite2022-05-13
GHSA
GHSA-xf7r-8x9r-r7xg: There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 42022-05-13
OSV
CVE-2018-10963: The TIFFWriteDirectorySec() function in tif_dirwrite2018-05-10
OSV
CVE-2017-13726: There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 42017-08-29

📋Vendor Advisories

5
Red Hat
libtiff: reachable assertion in TIFFWriteDirectorySec function in tif_dirwrite.c2018-05-09
Ubuntu
LibTIFF vulnerabilities2018-03-20
Debian
CVE-2018-10963: tiff - The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 ...2018
Red Hat
libtiff: Reachable assertion abort in the function TIFFWriteDirectorySec()2017-08-21
Debian
CVE-2017-13726: tiff - There is a reachable assertion abort in the function TIFFWriteDirectorySec() in ...2017

💬Community

4
Bugzilla
CVE-2017-13726 libtiff: Reachable assertion abort in the function TIFFWriteDirectorySec()2017-09-06
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 mingw-libtiff: various flaws [fedora-all]2017-07-24
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 mingw-libtiff: various flaws [epel-7]2017-07-24
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 libtiff: various flaws [fedora-all]2017-07-24