CVE-2017-11335: Buffer Overflow
Last updated 24 July 2024
Other sources
There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tifzip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11335?
CVE-2017-11335 has been classified with a high severity level due to the potential for remote denial of service caused by a heap-based buffer overflow.
How do I fix CVE-2017-11335?
To mitigate CVE-2017-11335, upgrade to LibTIFF version 4.2.0-1+deb11u5 or higher.
Which versions of LibTIFF are affected by CVE-2017-11335?
CVE-2017-11335 specifically affects LibTIFF version 4.0.8.
What impact does CVE-2017-11335 have on systems?
CVE-2017-11335 can lead to a denial of service, potentially making systems unresponsive when processing certain crafted images.
Is CVE-2017-11335 easy to exploit?
Yes, CVE-2017-11335 may be exploited through specially crafted input files which can be easily generated.