First published: Sun Mar 17 2019(Updated: )
** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libtiff Libtiff | =4.0.8 | |
openSUSE Leap | =42.2 | |
openSUSE Leap | =42.3 | |
SUSE Linux Enterprise Desktop | =12-sp2 | |
SUSE Linux Enterprise Desktop | =12-sp3 | |
SUSE Linux Enterprise Server | =12-sp2 | |
SUSE Linux Enterprise Server | =12-sp2 | |
SUSE Linux Enterprise Server | =12-sp3 | |
SUSE Linux Enterprise Software Development Kit | =12-sp2 | |
SUSE Linux Enterprise Software Development Kit | =12-sp3 | |
=4.0.8 | ||
=42.2 | ||
=42.3 | ||
=12-sp2 | ||
=12-sp3 | ||
=12-sp2 | ||
=12-sp2 | ||
=12-sp3 | ||
=12-sp2 | ||
=12-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this LibTIFF vulnerability is CVE-2017-16232.
CVE-2017-16232 has a severity rating of high.
The affected software for CVE-2017-16232 includes LibTIFF 4.0.8, openSUSE Leap 42.2 and 42.3, SUSE Linux Enterprise Desktop 12-sp2 and 12-sp3, SUSE Linux Enterprise Server 12-sp2 and 12-sp3, and SUSE Linux Enterprise Software Development Kit 12-sp2 and 12-sp3.
CVE-2017-16232 allows attackers to cause a denial of service by exploiting multiple memory leak vulnerabilities in LibTIFF 4.0.8.
Third parties were unable to reproduce the issue of CVE-2017-16232.