Back

HIGH

libtiff: heap-based use after free in tiff2pdf.c:t2p_writeproc

Published Dec 29, 2017

Description

In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

Affected products

Remediation

Red Hat statement

Red Hat engineering was unable to reproduce this issue. Also there was no update from upstream about the ability to validate this bug. As a result there would be no fixes available for this CVE.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 29, 2017
Updated Aug 5, 2024
Reserved Dec 29, 2017
CISA Vulnrichment
Updated Apr 22, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 29, 2017