CVE-2017-12944: High severity LibTIFF libtiff vulnerability
Last updated 25 August 2025
Other sources
The TIFFReadDirEntryArray function in tifread.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tifdirread.c during a tiff2pdf invocation.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1 - Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Fixed in 4.0.8
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12944?
CVE-2017-12944 has a medium severity rating due to its potential to cause application crashes.
How do I fix CVE-2017-12944?
To fix CVE-2017-12944, upgrade to LibTIFF version 4.2.0-1+deb11u5 or later, or to any version higher than 4.0.8.
What vulnerabilities does CVE-2017-12944 exploit?
CVE-2017-12944 exploits a memory allocation issue in the TIFFReadDirEntryArray function.
Which software versions are affected by CVE-2017-12944?
Affected versions include LibTIFF 4.0.8 and any other versions prior to 4.2.0-1+deb11u5.
Can CVE-2017-12944 lead to remote attacks?
Yes, CVE-2017-12944 can allow remote attackers to cause denial of service through an application crash.