CVE-2017-9147: Medium severity LibTIFF libtiff vulnerability
Last updated 25 August 2025
Other sources
LibTIFF 4.0.7 has an invalid read in the TIFFVGetField function in tifdir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9147?
CVE-2017-9147 has a medium severity rating as it may lead to a denial of service through a crash.
Which versions of LibTIFF are affected by CVE-2017-9147?
CVE-2017-9147 affects LibTIFF version 4.0.7 and certain Debian package versions of tiff.
How do I fix CVE-2017-9147?
To mitigate CVE-2017-9147, update to a non-vulnerable version of LibTIFF or the affected Debian packages.
What does CVE-2017-9147 exploit in LibTIFF?
CVE-2017-9147 exploits an invalid read in the _TIFFVGetField function within tif_dir.c.
Can CVE-2017-9147 be exploited remotely?
Yes, CVE-2017-9147 can be exploited remotely via a crafted TIFF file.