CVE-2017-13727Reachable Assertion in Libtiff

CWE-617Reachable Assertion10 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
0.6%
top 29.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 13

Description

There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.8
debiandebian/tiff< tiff 4.0.8-5 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-6wx6-w4jp-vgm2: There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 42022-05-13
OSV
CVE-2017-13727: There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 42017-08-29

📋Vendor Advisories

3
Ubuntu
LibTIFF vulnerabilities2018-03-20
Red Hat
libtiff: Reachable assertion abort in the function TIFFWriteDirectoryTagSubifd()2017-08-21
Debian
CVE-2017-13727: tiff - There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd...2017

💬Community

4
Bugzilla
CVE-2017-13727 libtiff: Reachable assertion abort in the function TIFFWriteDirectoryTagSubifd()2017-09-06
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 mingw-libtiff: various flaws [fedora-all]2017-07-24
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 mingw-libtiff: various flaws [epel-7]2017-07-24
Bugzilla
CVE-2017-11335 CVE-2017-12944 CVE-2017-13726 CVE-2017-13727 CVE-2017-16232 libtiff: various flaws [fedora-all]2017-07-24