CVE-2017-7595: Divide by Zero
Last updated 24 July 2024
Other sources
The JPEGSetupEncode function in tiffjpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u6Fixed in 4.5.0-6+deb12u2Fixed in 4.5.0-6+deb12u1Fixed in 4.7.0-3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7595?
CVE-2017-7595 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2017-7595?
To fix CVE-2017-7595, you should update your LibTIFF to a patched version that addresses the divide-by-zero error.
What software versions are affected by CVE-2017-7595?
CVE-2017-7595 affects LibTIFF version 4.0.7 and specific Debian packages like tiff versions 4.2.0-1+deb11u5 and 4.5.1+git230720-5.
What is the nature of the vulnerability in CVE-2017-7595?
CVE-2017-7595 is a denial of service vulnerability caused by a divide-by-zero error in the JPEGSetupEncode function.
Can CVE-2017-7595 be exploited remotely?
Yes, CVE-2017-7595 can be exploited remotely by attackers sending specially crafted images.