REDHAT-BUG-1524284: Medium severity tiff vulnerability
The pal2rgb tool (tools/pal2rgb.c) in LibTIFF 4.0.9 is vulnerable to a heap-based bufferflow when parsing a specially crafted .tif file. A remote attacker could exploit this to cause an application crash (denial of service) or other possible unspecified impact.
References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-17095 http://www.openwall.com/lists/oss-security/2017/11/30/3 http://www.cvedetails.com/cve/CVE-2017-17095/ http://bugzilla.maptools.org/showbug.cgi?id=2750
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1524284?
The severity of REDHAT-BUG-1524284 is critical due to the potential for denial of service and application crashes.
How do I fix REDHAT-BUG-1524284?
To fix REDHAT-BUG-1524284, update LibTIFF to the latest version that addresses this vulnerability.
Who is affected by REDHAT-BUG-1524284?
Users of LibTIFF 4.0.9 and earlier versions are affected by REDHAT-BUG-1524284.
What type of vulnerability is REDHAT-BUG-1524284?
REDHAT-BUG-1524284 is a heap-based buffer overflow vulnerability.
What could happen if REDHAT-BUG-1524284 is exploited?
If exploited, REDHAT-BUG-1524284 could lead to application crashes or denial of service.