CVE-2017-5563

SOURCE - nist

Summary

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.

EPSS Score: 0.00538 (0.772)

Common Weakness Enumeration (CWE)

SOURCE - nist

Out-of-bounds Read

SOURCE - redhat

Heap-based Buffer Overflow


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/tiffdebdebian12>=4.5.0-6+deb12u1Not yet available
debian/tiffdebdebian11>=4.2.0-1+deb11u5Not yet available
debian/tiffdebdebianunstable>=4.5.1+git230720-4Not yet available
debian/tiffdebdebian13>=4.5.1+git230720-4Not yet available
debian/tiffdebdebian10>=4.1.0+git191117-2~deb10u4Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

2.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

8.8high

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

2.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

8.8low

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.3medium