CVE-2017-17973

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
libtifflibtiff
4.0.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tiff
artful
ignored
bionic
ignored
cosmic
ignored
disco
ignored
trusty
ignored
xenial
ignored
zesty
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libtiff5
suse enterprise sap 12 SP3
4.0.9-44.10.1
fixed
suse enterprise sap 12 SP5
4.0.9-44.30.1
fixed
suse enterprise server 12 SP3
4.0.9-44.10.1
fixed
suse enterprise server 12 SP5
4.0.9-44.30.1
fixed
libtiff5-32bit
suse enterprise sap 12 SP3
4.0.9-44.10.1
fixed
suse enterprise sap 12 SP5
4.0.9-44.30.1
fixed
suse enterprise server 12 SP3
4.0.9-44.10.1
fixed
suse enterprise server 12 SP5
4.0.9-44.30.1
fixed
tiff
suse enterprise sap 12 SP3
4.0.9-44.10.1
fixed
suse enterprise sap 12 SP5
4.0.9-44.30.1
fixed
suse enterprise server 12 SP3
4.0.9-44.10.1
fixed
suse enterprise server 12 SP5
4.0.9-44.30.1
fixed