CVE-2017-13727: Medium severity tiff vulnerability
Published Aug 29, 2017
·Updated
Last updated 24 July 2024
Other sources
There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tifdirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
Affected Software
2 affected componentsFixes available
LibTIFF libtiff=4.0.8
debian/tiff
4.2.0-1+deb11u54.2.0-1+deb11u64.5.0-6+deb12u24.5.0-6+deb12u14.7.0-3
Remediation
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Aug 5, 2024
Data Sourced
via Launchpad·05:51 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·05:58 AM
RemedyDescriptionSeverityAffected Software
Apr 10, 2025
Data Sourced
via Debian·11:43 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-13727?
CVE-2017-13727 has a severity rating that indicates it can lead to remote denial of service attacks.
2
How do I fix CVE-2017-13727?
To fix CVE-2017-13727, upgrade to a patched version of LibTIFF that is newer than 4.0.8.
3
What software is affected by CVE-2017-13727?
CVE-2017-13727 affects LibTIFF versions 4.0.8 and specific Debian package versions of TIFF.
4
What happens when CVE-2017-13727 is exploited?
Exploitation of CVE-2017-13727 results in a reachable assertion abort, potentially crashing the application.
5
Is CVE-2017-13727 specific to any operating system?
CVE-2017-13727 is primarily associated with Debian systems, but any systems using affected LibTIFF versions can be vulnerable.