Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 635214 (CVE-2017-10688, CVE-2017-11613)

Summary: <media-libs/tiff-4.0.9: Multiple vulnerabilities
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: graphics+disabled
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A4 [noglsa cve]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2017-10-23 19:11:11 UTC
CVE-2017-13727 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-13727):
  There is a reachable assertion abort in the function
  TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c
  and a SubIFD tag. A crafted input will lead to a remote denial of service
  attack.

CVE-2017-13726 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-13726):
  There is a reachable assertion abort in the function TIFFWriteDirectorySec()
  in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted
  input will lead to a remote denial of service attack.

CVE-2017-12944 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12944):
  The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles
  memory allocation for short files, which allows remote attackers to cause a
  denial of service (allocation failure and application crash) in the
  TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation.

CVE-2017-11613 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-11613):
  In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen
  function. A crafted input will lead to a denial of service attack. During
  the TIFFOpen process, td_imagelength is not checked. The value of
  td_imagelength can be directly controlled by an input file. In the
  ChopUpSingleUncompressedStrip function, the _TIFFCheckMalloc function is
  called based on td_imagelength. If we set the value of td_imagelength close
  to the amount of system memory, it will hang the system or trigger the OOM
  killer.

CVE-2017-10688 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10688):
  In LibTIFF 4.0.8, there is a assertion abort in the
  TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted
  input will lead to a remote denial of service attack.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-06-11 15:18:42 UTC
GLSA Vote: No

tree is clean