CVE-2017-17973 PUBLISHED

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

EPSS 0.63% · 70.2th percentile

Risk Scores

EPSS Score
0.63%
70.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTStiff0, 4.0.3-12.3ubuntu2, 4.0.5-1
Ubuntu:Pro:14.04:LTStiff4.0.3-7ubuntu0.11+esm15, 4.0.3-7ubuntu0.11+esm16, 4.0.3-7ubuntu0.11+esm7
Ubuntu:Pro:18.04:LTStiff0, 4.0.8-5, 4.0.8-6

Timeline

References

Open in Interactive Console →