bugzilla.maptools.org
http://bugzilla.maptools.org/show_bug.cgi?id=2693 CVE-2017-9147
MEDIUM
LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
Record summary
CVE-2017-9147 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds ReadExploitDB exploitby zhangtanNot analyzed1 file
References
6DSA-3903Vendor advisory
http://www.debian.org/security/2017/dsa-3903 98594vdb entry
http://www.securityfocus.com/bid/98594 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9147 USN-3606-1Vendor advisory
https://usn.ubuntu.com/3606-1 42301exploit
https://www.exploit-db.com/exploits/42301