CVE-2017-16232

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue.

References

http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html

http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html

http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html

http://seclists.org/fulldisclosure/2018/Dec/32

http://seclists.org/fulldisclosure/2018/Dec/47

http://www.openwall.com/lists/oss-security/2017/11/01/11

http://www.openwall.com/lists/oss-security/2017/11/01/3

http://www.openwall.com/lists/oss-security/2017/11/01/7

http://www.openwall.com/lists/oss-security/2017/11/01/8

http://www.securityfocus.com/bid/101696

Details

Source: MITRE

Published: 2019-03-21

Updated: 2019-10-03

Type: CWE-772

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (11 total)

IDNameProductFamilySeverity
151343EulerOS Virtualization for ARM 64 3.0.2.0 : libtiff (EulerOS-SA-2021-2119)NessusHuawei Local Security Checks
high
149107EulerOS 2.0 SP3 : compat-libtiff3 (EulerOS-SA-2021-1770)NessusHuawei Local Security Checks
high
147566EulerOS Virtualization 3.0.2.6 : libtiff (EulerOS-SA-2021-1439)NessusHuawei Local Security Checks
high
147129EulerOS Virtualization 3.0.6.6 : libtiff (EulerOS-SA-2021-1492)NessusHuawei Local Security Checks
high
146680EulerOS 2.0 SP2 : compat-libtiff3 (EulerOS-SA-2021-1285)NessusHuawei Local Security Checks
high
146160EulerOS 2.0 SP5 : compat-libtiff3 (EulerOS-SA-2021-1184)NessusHuawei Local Security Checks
high
146131EulerOS 2.0 SP5 : libtiff (EulerOS-SA-2021-1207)NessusHuawei Local Security Checks
high
132156EulerOS 2.0 SP3 : libtiff (EulerOS-SA-2019-2621)NessusHuawei Local Security Checks
high
131619EulerOS 2.0 SP2 : libtiff (EulerOS-SA-2019-2466)NessusHuawei Local Security Checks
critical
106060openSUSE Security Update : tiff (openSUSE-2018-31)NessusSuSE Local Security Checks
critical
106043SUSE SLED12 / SLES12 Security Update : tiff (SUSE-SU-2018:0073-1)NessusSuSE Local Security Checks
critical