CVE-2017-16232: High severity tiff vulnerability
DISPUTED LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tifopen.c, tiflzw.c, and tifaux.c. NOTE: Third parties were unable to reproduce the issue.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this LibTIFF vulnerability?
The vulnerability ID for this LibTIFF vulnerability is CVE-2017-16232.
What is the severity of CVE-2017-16232?
CVE-2017-16232 has a severity rating of high.
What is the affected software for CVE-2017-16232?
The affected software for CVE-2017-16232 includes LibTIFF 4.0.8, openSUSE Leap 42.2 and 42.3, SUSE Linux Enterprise Desktop 12-sp2 and 12-sp3, SUSE Linux Enterprise Server 12-sp2 and 12-sp3, and SUSE Linux Enterprise Software Development Kit 12-sp2 and 12-sp3.
How does CVE-2017-16232 allow attackers to cause a denial of service?
CVE-2017-16232 allows attackers to cause a denial of service by exploiting multiple memory leak vulnerabilities in LibTIFF 4.0.8.
Is CVE-2017-16232 easy to reproduce?
Third parties were unable to reproduce the issue of CVE-2017-16232.