CVE-2017-5225: Buffer Overflow
Published Jan 12, 2017
·Updated
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.
Affected Software
1 affected component
LibTIFF libtiff=4.0.7
Event History
Jan 12, 2017
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
via NVD·11:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5225?
CVE-2017-5225 is classified as a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2017-5225?
To fix CVE-2017-5225, upgrade to LibTIFF version 4.0.8 or later where the vulnerability has been patched.
3
What causes the CVE-2017-5225 vulnerability?
CVE-2017-5225 is caused by a heap buffer overflow in the tiffcp tool when processing a crafted BitsPerSample value.
4
What are the potential impacts of CVE-2017-5225?
The potential impacts of CVE-2017-5225 include denial of service (DoS) and the execution of arbitrary code.
5
Which versions of LibTIFF are affected by CVE-2017-5225?
CVE-2017-5225 affects LibTIFF version 4.0.7 specifically.