There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
http://bugzilla.maptools.org/show_bug.cgi?id=2727
http://www.securityfocus.com/bid/100524
Source: MITRE
Published: 2017-08-29
Updated: 2019-10-03
Type: CWE-617
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
135609 | EulerOS Virtualization 3.0.2.2 : libtiff (EulerOS-SA-2020-1447) | Nessus | Huawei Local Security Checks | high |
134524 | EulerOS Virtualization for ARM 64 3.0.2.0 : libtiff (EulerOS-SA-2020-1235) | Nessus | Huawei Local Security Checks | high |
131619 | EulerOS 2.0 SP2 : libtiff (EulerOS-SA-2019-2466) | Nessus | Huawei Local Security Checks | high |
130727 | EulerOS 2.0 SP3 : libtiff (EulerOS-SA-2019-2265) | Nessus | Huawei Local Security Checks | high |
130671 | EulerOS 2.0 SP5 : libtiff (EulerOS-SA-2019-2209) | Nessus | Huawei Local Security Checks | high |
121769 | Photon OS 2.0: Libtiff PHSA-2017-0050 | Nessus | PhotonOS Local Security Checks | high |
111899 | Photon OS 2.0: Curl / Libtiff / Linux PHSA-2017-0050 (deprecated) | Nessus | PhotonOS Local Security Checks | high |
110802 | openSUSE Security Update : tiff (openSUSE-2018-677) | Nessus | SuSE Local Security Checks | medium |
110763 | SUSE SLED12 / SLES12 Security Update : tiff (SUSE-SU-2018:1826-1) | Nessus | SuSE Local Security Checks | medium |
108513 | Ubuntu 14.04 LTS / 16.04 LTS : LibTIFF vulnerabilities (USN-3602-1) | Nessus | Ubuntu Local Security Checks | medium |
106414 | Debian DSA-4100-1 : tiff - security update | Nessus | Debian Local Security Checks | medium |
103761 | FreeBSD : libtiff -- Improper Input Validation (9b5a905f-e556-452f-a00c-8f070a086181) | Nessus | FreeBSD Local Security Checks | medium |
103093 | Debian DLA-1093-1 : tiff security update | Nessus | Debian Local Security Checks | medium |