Record summary

CVE-2017-9147 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBLibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds ReadExploitDB exploitby zhangtanNot analyzed1 file
ExploitDB

PoC details

References

6