CVE-2017-9937

SOURCE - nist

Summary

In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.

EPSS Score: 0.00145 (0.503)

Common Weakness Enumeration (CWE)

SOURCE - nist

Improper Restriction of Operations within the Bounds of a Memory Buffer

SOURCE - redhat

Improper Initialization


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/jbigkitdebdebian12>=2.1-6.1Not yet available
debian/jbigkitdebdebian13>=2.1-6.1Not yet available
debian/jbigkitdebdebian11>=2.1-3.1Not yet available
debian/jbigkitdebdebian10>=2.1-3.1Not yet available
debian/jbigkitdebdebianunstable>=2.1-6.1Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

2.8


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.5medium

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

2.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

6.5low

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.3low

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE