Heap Buffer Over-Read in LibTIFF Affecting BMP Image Processing
CVE-2017-9117
9.8CRITICAL
What is CVE-2017-9117?
In LibTIFF version 4.0.7, a vulnerability exists that allows for a heap-based buffer over-read when processing BMP images. The issue arises from the library's failure to verify that the biWidth and biHeight values in the bitmap-information header correspond to the actual input data. This could lead to unexpected behavior and potential data exposure for systems using this library.