CVE-2017-17095 PUBLISHED

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

EPSS 3.99% · 88.3th percentile

Risk Scores

EPSS Score
3.99%
88.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStiff0, 4.0.3-12.3ubuntu2, 4.0.5-1
Ubuntu:14.04:LTStiff4.0.3-7ubuntu0.2, 4.0.3-7ubuntu0.3, 4.0.3-7ubuntu0.4

Timeline

References

Open in Interactive Console →