CVE-2017-9404: Medium severity LibTIFF libtiff vulnerability
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tifojpeg.c, which allows attackers to cause a denial of service via a crafted file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.2.0-1+deb11u8Fixed in 4.5.0-6+deb12u4Fixed in 4.7.0-3+deb13u2Fixed in 4.7.0-3+deb13u3Fixed in 4.7.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9404?
CVE-2017-9404 is classified as a medium severity vulnerability due to its potential for denial of service.
How do I fix CVE-2017-9404?
To fix CVE-2017-9404, upgrade to LibTIFF versions 4.2.0-1+deb11u5 or later, or apply the relevant security updates provided by your operating system.
What is the impact of CVE-2017-9404?
The impact of CVE-2017-9404 is that it can lead to a denial of service through a memory leak when processing a specially crafted file.
Which versions of LibTIFF are affected by CVE-2017-9404?
Versions of LibTIFF prior to 4.2.0 are affected by CVE-2017-9404, specifically version 4.0.7.
Is CVE-2017-9404 specific to any operating system?
CVE-2017-9404 affects multiple operating systems including Debian and Ubuntu distributions that are running vulnerable versions of LibTIFF.