CVE-2017-17973: Use After Free
DISPUTED In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2pwriteproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue.
Other sources
In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2pwriteproc function in tiff2pdf.c
References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-17973 http://www.cvedetails.com/cve/CVE-2017-17973/ http://bugzilla.maptools.org/showbug.cgi?id=2769
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17973?
CVE-2017-17973 is classified as a use-after-free vulnerability which can potentially lead to arbitrary code execution.
How do I fix CVE-2017-17973?
To mitigate CVE-2017-17973, upgrade to a fixed version of LibTIFF that addresses this specific vulnerability.
What software is affected by CVE-2017-17973?
CVE-2017-17973 specifically affects LibTIFF version 4.0.8.
What type of vulnerability is CVE-2017-17973?
CVE-2017-17973 is a heap-based use-after-free vulnerability located in the t2p_writeproc function.
Is CVE-2017-17973 easy to exploit?
The exploitability of CVE-2017-17973 is uncertain due to a third-party report claiming inability to reproduce the issue.