CVE-2017-9117 - CVE House
Back to Database
Status published Medium CVE-2017-9117

In LibTIFF 4.0.6 and possibly other versions, the program processes...

Vulnerability Description

In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-9117

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

LibTIFF
Vulnerable Versions:
4.0.6

Timeline

Official Publish: May 21st, 2017
Last Modified: January 7th, 2025
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)