CVE-2017-5849: Medium severity fedoraproject fedora vulnerability
Published Mar 15, 2017
·Updated
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.
Affected Software
3 affected components
fedoraproject fedora=24
fedoraproject fedora=25
Netpbm Project Netpbm=10.47.63
Event History
Mar 15, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5849?
CVE-2017-5849 is classified as a denial of service vulnerability due to out-of-bounds read and write issues.
2
How do I fix CVE-2017-5849?
To resolve CVE-2017-5849, update to a patched version of Netpbm or Fedora that addresses this vulnerability.
3
What software is affected by CVE-2017-5849?
CVE-2017-5849 affects Netpbm version 10.47.63 and Fedora versions 24 and 25.
4
Can CVE-2017-5849 be exploited remotely?
Yes, CVE-2017-5849 can be exploited remotely via a crafted TIFF image file.
5
What type of attack does CVE-2017-5849 enable?
CVE-2017-5849 enables a denial of service attack that could crash applications processing malicious TIFF images.