CVE-2017-7596: Input Validation
Last updated 24 July 2024
Other sources
LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u6Fixed in 4.5.0-6+deb12u2Fixed in 4.5.0-6+deb12u1Fixed in 4.7.0-3 - Upgrade
Upgrade
libtiffto a version that resolves this vulnerability.Fixed in 4.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7596?
CVE-2017-7596 is considered a medium severity vulnerability that may lead to application crashes.
How do I fix CVE-2017-7596?
Fix CVE-2017-7596 by upgrading to the following versions: 4.2.0-1+deb11u5, 4.2.0-1+deb11u6, 4.5.0-6+deb12u1, or 4.5.0-6+deb12u2.
What software is affected by CVE-2017-7596?
CVE-2017-7596 affects LibTIFF version 4.0.7 and the related Debian tiff package.
Can CVE-2017-7596 be exploited remotely?
Yes, CVE-2017-7596 can potentially be exploited remotely by attackers using specially crafted images.
What is the potential impact of CVE-2017-7596?
The potential impact of CVE-2017-7596 includes denial of service due to application crashes and possibly other unspecified effects.