ZeroHour

CVE-2017-9815

CVSS 3.0
6.5 medium
EPSS
2%p74
Published
()
Modified
Description

In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via a crafted file.

Vendors
libtiffcanonical
Products
libtiff, ubuntu linux
Weakness
CWE-772
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.