8.8
CVSSv3

CVE-2017-17942

Published: 28/12/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 4.0.9

Vendor Advisories

Debian Bug report logs - #885579 tiff: CVE-2017-17942: heap-buffer-overflow in PackBitsEncode function Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 28 Dec 2017 10:12:01 UTC Severity: important Tags: security, ...
In LibTIFF 409, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbitsc ...