CVE-2017-13726: Medium severity tiff vulnerability
Published Aug 29, 2017
·Updated
Last updated 24 July 2024
Other sources
There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tifdirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
Affected Software
2 affected componentsFixes available
LibTIFF libtiff=4.0.8
debian/tiff
4.2.0-1+deb11u54.2.0-1+deb11u64.5.0-6+deb12u24.5.0-6+deb12u14.7.0-3
Remediation
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Aug 5, 2024
Data Sourced
via Launchpad·05:51 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·05:58 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-13726?
CVE-2017-13726 is classified as a denial of service vulnerability that can cause remote application crashes.
2
How do I fix CVE-2017-13726?
To fix CVE-2017-13726, upgrade to LibTIFF version 4.2.0-1+deb11u5 or later.
3
What software is affected by CVE-2017-13726?
CVE-2017-13726 affects LibTIFF version 4.0.8 and certain Debian packages of tiff.
4
What is the impact of CVE-2017-13726?
The impact of CVE-2017-13726 is that it may lead to a remote denial of service due to a reachable assertion abort.
5
Can CVE-2017-13726 be exploited remotely?
Yes, CVE-2017-13726 can be exploited remotely by crafting specific input that triggers the vulnerability.