CVE-2017-7599
Ubuntu Security Notice USN-3602-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
LibTIFF 4.0.7 tiene un problema de comportamiento "fuera de rango de valores representables de tipo corto" no definido, lo que podrían permitir a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o posiblemente tener otro impacto no especificado a través de una imagen manipulada.
It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-09 CVE Reserved
- 2017-04-09 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97505 | Third Party Advisory | |
http://www.securityfocus.com/bid/97508 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://blogs.gentoo.org/ago/2017/04/01/libtiff-multiple-ubsan-crashes | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3844 | 2018-03-22 | |
https://security.gentoo.org/glsa/201709-27 | 2018-03-22 | |
https://usn.ubuntu.com/3602-1 | 2018-03-22 |