Medium severity6.5NVD Advisory· Published Jul 26, 2017· Updated May 13, 2026
CVE-2017-11613
CVE-2017-11613
Description
In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip function, the _TIFFCheckMalloc function is called based on td_imagelength. If we set the value of td_imagelength close to the amount of system memory, it will hang the system or trigger the OOM killer.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/99977nvdThird Party AdvisoryVDB Entry
- gist.github.com/dazhouzhou/1a3b7400547f23fe316db303ab9b604fnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/05/msg00022.htmlnvd
- lists.debian.org/debian-lts-announce/2018/07/msg00002.htmlnvd
- usn.ubuntu.com/3606-1/nvd
- www.debian.org/security/2018/dsa-4349nvd
News mentions
0No linked articles in our index yet.