Vulnerability Name:

CVE-2017-11335 (CCN-129030)

Assigned:2017-07-14
Published:2017-07-14
Updated:2018-03-22
Summary:There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tif_zip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution attack.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Bugzilla - Bug 2715
tiff2pdf: heap based buffer write overflow

Source: MISC
Type: Issue Tracking
http://bugzilla.maptools.org/show_bug.cgi?id=2715

Source: MITRE
Type: CNA
CVE-2017-11335

Source: XF
Type: UNKNOWN
libtiff-cve201711335-dos(129030)

Source: UBUNTU
Type: UNKNOWN
USN-3602-1

Source: DEBIAN
Type: UNKNOWN
DSA-4100

Vulnerable Configuration:Configuration 1:
  • cpe:/a:libtiff:libtiff:4.0.8:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:libtiff:libtiff:4.0.8:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201711335
    V
    CVE-2017-11335
    2022-05-20
    oval:org.opensuse.security:def:29495
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:35280
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:31334
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:30283
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:34590
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:31700
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:29441
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:30115
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:31247
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:34500
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:33694
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:30104
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:31656
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:30103
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:32949
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:31634
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:36429
    P
    kopete-devel-4.3.5-0.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36387
    P
    cvs-doc-1.12.12-144.23.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31190
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:34443
    P
    Security update for postgresql12 (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:33650
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:30189
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:33084
    P
    Security update for tomcat (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:28929
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:33626
    P
    Security update for xen (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:31098
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:34332
    P
    Security update for curl (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:28860
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:35644
    P
    tar-1.20-23.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35603
    P
    libsnmp15-32bit-5.4.2.1-8.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35749
    P
    libgtop-2.28.0-1.2.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35705
    P
    gd-2.0.36.RC1-52.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35677
    P
    clamav-0.97.3-0.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35638
    P
    squid-2.7.STABLE5-2.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35589
    P
    libltdl7-2.2.6-2.131.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35530
    P
    clamav-0.96-0.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35223
    P
    Security update for liblouis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31595
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28413
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35122
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31546
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28378
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:34986
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31490
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:27740
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:34902
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27696
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34891
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27682
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:34372
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34890
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27643
    P
    Security update for libssh2
    2020-12-01
    oval:org.opensuse.security:def:27594
    P
    Security update for GraphicsMagick
    2020-12-01
    oval:org.opensuse.security:def:30966
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27541
    P
    pwlib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30892
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:27390
    P
    dhcp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30881
    P
    Security update for file-roller (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27306
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33587
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30320
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30880
    P
    Security update for file
    2020-12-01
    oval:org.opensuse.security:def:27249
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33538
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:27168
    P
    ldapsmb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33481
    P
    Security update for libnetpbm
    2020-12-01
    oval:org.opensuse.security:def:29645
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:27040
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33324
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29601
    P
    Security update for automake
    2020-12-01
    oval:org.opensuse.security:def:26976
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33236
    P
    ppc64-diag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29583
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26965
    P
    libproxy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33179
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29544
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26964
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34965
    P
    Security update for fuse (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34921
    P
    Security update for evolution-data-server
    2020-12-01
    oval:org.opensuse.security:def:32870
    P
    glibc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29288
    P
    Security update for OFED
    2020-12-01
    oval:org.opensuse.security:def:34895
    P
    Security update for cyrus-imapd (Important)
    2020-12-01
    oval:org.opensuse.security:def:32859
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29203
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34856
    P
    Security update for cifs-utils (Important)
    2020-12-01
    oval:org.opensuse.security:def:31592
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32858
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29146
    P
    Security update for kvm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34807
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31554
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29060
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:34749
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30916
    P
    Security update for gcc48 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30872
    P
    Security update for expat (Important)
    2020-12-01
    oval:org.opensuse.security:def:30852
    P
    Security update for djvulibre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28849
    P
    Security update for xalan-j2
    2020-12-01
    oval:org.opensuse.security:def:30813
    P
    Recommended udpate for SUSE Manager Client Tools (Low)
    2020-12-01
    oval:org.opensuse.security:def:28848
    P
    Security update for wpa_supplicant (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34345
    P
    Security update for squid3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30764
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34209
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30709
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34125
    P
    Security update for netpbm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30554
    P
    Security update for libqt4
    2020-12-01
    oval:org.opensuse.security:def:34114
    P
    Security update for nagios (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30467
    P
    Security update for apache2-mod_nss
    2020-12-01
    oval:org.opensuse.security:def:32377
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34113
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30410
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32338
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30321
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35370
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:201711335000
    V
    CVE-2017-11335 on Ubuntu 17.10 (artful) - low.
    2017-07-17
    oval:com.ubuntu.xenial:def:2017113350000000
    V
    CVE-2017-11335 on Ubuntu 16.04 LTS (xenial) - low.
    2017-07-17
    oval:com.ubuntu.trusty:def:201711335000
    V
    CVE-2017-11335 on Ubuntu 14.04 LTS (trusty) - low.
    2017-07-17
    oval:com.ubuntu.xenial:def:201711335000
    V
    CVE-2017-11335 on Ubuntu 16.04 LTS (xenial) - low.
    2017-07-17
    BACK
    libtiff libtiff 4.0.8
    libtiff libtiff 4.0.8