CVE-2017-9147 PUBLISHED

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

EPSS 3.79% · 88.0th percentile

Risk Scores

EPSS Score
3.79%
88.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStiff0, 4.0.3-12.3ubuntu2, 4.0.5-1

Timeline

References

Open in Interactive Console →