CVE-2017-7597: Input Validation
Last updated 24 July 2024
Other sources
tifdirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u6Fixed in 4.5.0-6+deb12u2Fixed in 4.5.0-6+deb12u1Fixed in 4.7.0-3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7597?
CVE-2017-7597 has a medium severity level as it can lead to application crashes and potential denial of service.
How do I fix CVE-2017-7597?
To fix CVE-2017-7597, update to versions 4.2.0-1+deb11u5, 4.2.0-1+deb11u6, 4.5.0-6+deb12u2, 4.5.0-6+deb12u1, or 4.5.1+git230720-5 of the tiff package.
What causes the CVE-2017-7597 vulnerability?
CVE-2017-7597 is caused by an undefined behavior issue related to floating point representation in the tif_dirread.c file.
What are the potential impacts of CVE-2017-7597?
The potential impacts of CVE-2017-7597 include denial of service resulting from application crashes and other unspecified effects.
Which versions of LibTIFF are affected by CVE-2017-7597?
CVE-2017-7597 affects LibTIFF version 4.0.7 specifically.