Back

MEDIUM

libtiff: Memory leak via corrupt td_imagelength in TIFFOpen function

Published Jul 26, 2017

Description

In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip function, the _TIFFCheckMalloc function is called based on td_imagelength. If we set the value of td_imagelength close to the amount of system memory, it will hang the system or trigger the OOM killer.

Affected products

Remediation

Red Hat statement

Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 26, 2017
Updated Aug 5, 2024
Reserved Jul 25, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Jul 26, 2017