CVE-2017-5225
12.01.2017, 11:59
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libtiff | libtiff | 4.0.7 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libtiff-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff5 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff5-32bit |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff6 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libtiff6-32bit |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| tiff |
|
Common Weakness Enumeration
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
- CWE-122 - Heap-based Buffer OverflowA heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
References