First published: Fri Dec 29 2017(Updated: )
** DISPUTED ** In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIFF | =4.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17973 is classified as a use-after-free vulnerability which can potentially lead to arbitrary code execution.
To mitigate CVE-2017-17973, upgrade to a fixed version of LibTIFF that addresses this specific vulnerability.
CVE-2017-17973 specifically affects LibTIFF version 4.0.8.
CVE-2017-17973 is a heap-based use-after-free vulnerability located in the t2p_writeproc function.
The exploitability of CVE-2017-17973 is uncertain due to a third-party report claiming inability to reproduce the issue.