Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-9936. PoCs published by team OWL337.
AI-analyzed exploit summary This exploit demonstrates a memory leak vulnerability in libtiff's tiff2ps and tiff2pdf utilities, triggered by a malformed input file. The AddressSanitizer output confirms significant memory leaks, indicating a denial-of-service (DoS) condition.
Description
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
Exploits (1)
This exploit demonstrates a memory leak vulnerability in libtiff's tiff2ps and tiff2pdf utilities, triggered by a malformed input file. The AddressSanitizer output confirms significant memory leaks, indicating a denial-of-service (DoS) condition.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H