CVE-2017-9117

SOURCE - nist

Summary

In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.

EPSS Score: 0.00623 (0.789)

Common Weakness Enumeration (CWE)

SOURCE - nist

Out-of-bounds Read

SOURCE - redhat

Out-of-bounds Read


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/tiffdebdebian12>=4.5.0-6+deb12u1Not yet available
debian/tiffdebdebian10>=4.1.0+git191117-2~deb10u4Not yet available
debian/tiffdebdebian13>=4.5.1+git230720-4Not yet available
debian/tiffdebdebianunstable>=4.5.1+git230720-4Not yet available
debian/tiffdebdebian11>=4.2.0-1+deb11u5Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.8critical

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

9.8low

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.3medium

suse

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

5.3medium

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE