CVE-2017-10688
HIGHLibTIFF 4.0.8 - Denial of Service via TIFFWriteDirectoryTagCheckedLong8Array Assertion Abort
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-10688. PoCs published by team OWL337.
AI-analyzed exploit summary This exploit triggers a denial-of-service (DoS) condition in LibTIFF by causing an assertion failure in the `TIFFWriteDirectoryTagCheckedLong8Array` function when processing a malformed TIFF file. The PoC demonstrates the crash via a crafted TIFF file processed by the `tiffset` utility.
Description
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack.
Exploits (1)
This exploit triggers a denial-of-service (DoS) condition in LibTIFF by causing an assertion failure in the `TIFFWriteDirectoryTagCheckedLong8Array` function when processing a malformed TIFF file. The PoC demonstrates the crash via a crafted TIFF file processed by the `tiffset` utility.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H