SB2017032412 - Multiple vulnerabilities in LibTIFF
Published: March 24, 2017 Updated: May 21, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2017-7597)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
2) Input validation error (CVE-ID: CVE-2017-7599)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
3) Input validation error (CVE-ID: CVE-2017-7600)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
4) Out-of-bounds read (CVE-ID: CVE-2016-10271)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in tools/tiffcrop.c in LibTIFF 4.0.7. A remote attacker can perform a denial of service (heap-based buffer over-read and buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 1" and libtiff/tif_fax3.c:413:13.
5) Heap-based buffer overflow (CVE-ID: CVE-2016-10272)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in LibTIFF 4.0.7. A remote attacker can use a crafted TIFF image to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.
References
- http://www.debian.org/security/2017/dsa-3844
- http://www.securityfocus.com/bid/97504
- https://blogs.gentoo.org/ago/2017/04/01/libtiff-multiple-ubsan-crashes
- https://security.gentoo.org/glsa/201709-27
- https://usn.ubuntu.com/3602-1/
- http://www.securityfocus.com/bid/97505
- http://www.securityfocus.com/bid/97508
- http://www.securityfocus.com/bid/97199
- https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/
- https://github.com/vadz/libtiff/commit/9657bbe3cdce4aaa90e07d50c1c70ae52da0ba6a
- http://www.securityfocus.com/bid/97197