CVE-2017-10688 PUBLISHED

In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack.

EPSS 6.84% · 91.3th percentile

Risk Scores

EPSS Score
6.84%
91.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStiff0, 4.0.3-12.3ubuntu2, 4.0.5-1
Ubuntu:14.04:LTStiff4.0.3-7ubuntu0.1, 4.0.3-7ubuntu0.2, 4.0.3-7ubuntu0.3

Timeline

References

Open in Interactive Console →