CVE-2017-5563: High severity LibTIFF libtiff vulnerability
Last updated 25 August 2025
Other sources
LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tiflzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5563?
CVE-2017-5563 is classified as a high severity vulnerability due to its potential to cause denial of service or arbitrary code execution.
How do I fix CVE-2017-5563?
To fix CVE-2017-5563, upgrade to a version of LibTIFF that is higher than 4.0.7.
What exploit types are associated with CVE-2017-5563?
CVE-2017-5563 can be exploited to achieve either denial of service or remote code execution through crafted BMP images.
Which versions of LibTIFF are affected by CVE-2017-5563?
LibTIFF version 4.0.7 is specifically vulnerable to CVE-2017-5563.
Is it safe to use software that depends on affected versions of LibTIFF for CVE-2017-5563?
No, using software that relies on affected versions of LibTIFF poses a security risk and should be avoided until patched.