CVE-2017-9937

EUVD-2017-18847
In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
libtifflibtiff
𝑥
≤ 4.0.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jbigkit
bookworm
unimportant
bullseye
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jbigkit
artful
ignored
bionic
Fixed 2.1-3.1ubuntu0.18.04.1
released
cosmic
ignored
disco
ignored
eoan
ignored
focal
Fixed 2.1-3.1ubuntu0.20.04.1
released
groovy
ignored
hirsute
ignored
impish
ignored
jammy
Fixed 2.1-3.1ubuntu0.22.04.1
released
kinetic
Fixed 2.1-3.1ubuntu0.22.10.1
released
lunar
Fixed 2.1-6ubuntu1
released
trusty
Fixed 2.0-2ubuntu4.1+esm1
released
xenial
Fixed 2.1-3.1ubuntu0.1~esm1
released
yakkety
ignored
zesty
ignored