CVE-2017-7593
MEDIUMLibTIFF 4.0.7 - Info Disclosure
Title source: llmDescription
tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
References (5)
Scores
CVSS v3
5.5
EPSS
0.0036
EPSS Percentile
57.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-119
Status
published
Affected Products (2)
libtiff/libtiff
n/a/n/a
Timeline
Published
Apr 09, 2017
Tracked Since
Feb 18, 2026