Memory Leak Vulnerabilities in LibTIFF Affects Multiple Applications
CVE-2017-16232

7.5HIGH

Key Information:

Vendor

Libtiff

Status
Vendor
CVE Published:
21 March 2019

What is CVE-2017-16232?

LibTIFF version 4.0.8 is plagued by several memory leak vulnerabilities that could potentially lead to denial of service attacks due to excessive memory consumption. Attackers can exploit these memory leaks in various components, as seen in tif_open.c, tif_lzw.c, and tif_aux.c. Although third-party attempts to reproduce the issues were unsuccessful, it highlights an area of concern for those utilizing LibTIFF in their applications, necessitating prompt attention and remediation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-16232 : Memory Leak Vulnerabilities in LibTIFF Affects Multiple Applications