Executive brief
LibTIFF is a widely used library for processing TIFF image files in various applications and operating systems. A vulnerability exists that allows a remote attacker to crash applications using this library by providing a specially crafted image file. This results in a denial of service, potentially disrupting business operations that rely on automated image processing or document management.
Technical details
A divide-by-zero vulnerability exists in the _TIFFFax3fillruns function within tif_fax3.c of libtiff. The flaw is triggered when the library processes a specially crafted TIFF image, specifically when using tools like tiffcrop that invoke Fax3 decoding routines. An attacker can exploit this by providing a malicious image file to an application linked against libtiff, leading to an arithmetic exception and subsequent process crash. This is a remote, unauthenticated attack vector requiring no user interaction beyond the application attempting to process the file. The issue was addressed in libtiff version 4.0.6 and later.
Affected products
- LibTIFF libtiff before 4.0.6
Timeline
- 2016-06-15: disclosed: Public disclosure on oss-security mailing list
- 2017-01-09: advisory: Gentoo security advisory released
- 2017-01-13: patched: Debian released security updates for jessie and sid
- 2017-01-20: advisory: NVD publication date