CVE-2017-9117: Medium severity LibTIFF libtiff vulnerability
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).
Other sources
In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1 - Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Fixed in 4.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9117?
CVE-2017-9117 has been identified as a moderate severity vulnerability.
How do I fix CVE-2017-9117?
To fix CVE-2017-9117, upgrade LibTIFF to version 4.0.7 or later.
Which versions of software are affected by CVE-2017-9117?
CVE-2017-9117 affects LibTIFF versions prior to 4.0.7, and certain Debian and Ubuntu packages up to specific versions.
What type of vulnerability is CVE-2017-9117?
CVE-2017-9117 is a heap-based buffer over-read vulnerability related to BMP image processing.
In which applications can CVE-2017-9117 be exploited?
CVE-2017-9117 can be exploited in applications that utilize the LibTIFF library for processing BMP images.