1
PublicDateAtUSN: 2017-05-22
2
Candidate: CVE-2017-9147
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9147
6
https://usn.ubuntu.com/usn/usn-3606-1
8
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in
9
tif_dir.c, which might allow remote attackers to cause a denial of service
10
(crash) via a crafted TIFF file.
13
ratliff> reproducer errors out on precise, trusty rather than crashing
14
mdeslaur> same problem as CVE-2015-7554
16
http://bugzilla.maptools.org/show_bug.cgi?id=2693
17
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863185
18
http://bugzilla.maptools.org/show_bug.cgi?id=2580
24
upstream_tiff: released (4.0.8-2)
25
precise/esm_tiff: not-affected
26
trusty_tiff: not-affected
27
vivid/stable-phone-overlay_tiff: ignored (reached end-of-life)
28
vivid/ubuntu-core_tiff: DNE
29
xenial_tiff: released (4.0.6-1ubuntu0.4)
30
yakkety_tiff: ignored (reached end-of-life)
31
zesty_tiff: ignored (reached end-of-life)
32
artful_tiff: not-affected (4.0.8-4)
33
devel_tiff: not-affected (4.0.8-4)