First published: Wed Mar 15 2017(Updated: )
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =24 | |
Fedora | =25 | |
Netpbm | =10.47.63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5849 is classified as a denial of service vulnerability due to out-of-bounds read and write issues.
To resolve CVE-2017-5849, update to a patched version of Netpbm or Fedora that addresses this vulnerability.
CVE-2017-5849 affects Netpbm version 10.47.63 and Fedora versions 24 and 25.
Yes, CVE-2017-5849 can be exploited remotely via a crafted TIFF image file.
CVE-2017-5849 enables a denial of service attack that could crash applications processing malicious TIFF images.