Bug 1530912 (CVE-2017-17973) - CVE-2017-17973 libtiff: heap-based use after free in tiff2pdf.c:t2p_writeproc
Summary: CVE-2017-17973 libtiff: heap-based use after free in tiff2pdf.c:t2p_writeproc
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2017-17973
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20171229,repor...
Depends On: 1530913
Blocks: 1530914
TreeView+ depends on / blocked
 
Reported: 2018-01-04 06:55 UTC by Sam Fowler
Modified: 2019-06-08 22:35 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-01-22 03:52:35 UTC


Attachments (Terms of Use)

Description Sam Fowler 2018-01-04 06:55:52 UTC
In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-17973
http://www.cvedetails.com/cve/CVE-2017-17973/
http://bugzilla.maptools.org/show_bug.cgi?id=2769

Comment 1 Sam Fowler 2018-01-04 06:56:16 UTC
Created libtiff tracking bugs for this issue:

Affects: fedora-all [bug 1530913]

Comment 2 Huzaifa S. Sidhpurwala 2018-01-22 03:52:35 UTC
Analysis:

I am not able to reproduce this on any version of libtiff shipped with Red Hat Enterprise Linux or with the upstream version compiled with ASAN. Currently there is no response from upstream nor any response from the reporter of this flaw.

I am going to mark this issue as notaffected, until there is more information available.


Note You need to log in before you can comment on or make changes to this bug.