{"id":"CVE-2017-16232","details":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue","modified":"2026-07-08T05:50:21.260608926Z","published":"2019-03-21T15:59:56.530Z","related":["SUSE-SU-2018:0073-1","openSUSE-SU-2024:11461-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"42.2"},{"last_affected":"42.2"},{"introduced":"42.3"},{"last_affected":"42.3"}],"source":"CPE_STRING","vendor_product":"opensuse:leap","cpes":["cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"]},{"vendor_product":"suse:linux_enterprise_desktop","cpes":["cpe:2.3:o:suse:linux_enterprise_desktop:12:sp2:*:*:*:*:*:*","cpe:2.3:o:suse:linux_enterprise_desktop:12:sp3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12-sp2"},{"last_affected":"12-sp2"},{"introduced":"12-sp3"},{"last_affected":"12-sp3"}],"source":"CPE_STRING"},{"vendor_product":"suse:linux_enterprise_server","cpes":["cpe:2.3:o:suse:linux_enterprise_server:12:sp2:*:*:*:*:*:*","cpe:2.3:o:suse:linux_enterprise_server:12:sp2:*:*:*:*:raspberry_pi:*","cpe:2.3:o:suse:linux_enterprise_server:12:sp3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12-sp2"},{"last_affected":"12-sp2"},{"introduced":"12-sp2"},{"last_affected":"12-sp2"},{"introduced":"12-sp3"},{"last_affected":"12-sp3"}],"source":"CPE_STRING"},{"source":"CPE_STRING","vendor_product":"suse:linux_enterprise_software_development_kit","cpes":["cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp2:*:*:*:*:*:*","cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12-sp2"},{"last_affected":"12-sp2"},{"introduced":"12-sp3"},{"last_affected":"12-sp3"}]}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/11/01/11"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/11/01/3"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/11/01/7"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/11/01/8"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101696"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2018/Dec/32"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2018/Dec/47"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vadz/libtiff","events":[{"introduced":"4a25fa0efc03a4e71740efc748c24b93152b1807"},{"last_affected":"4a25fa0efc03a4e71740efc748c24b93152b1807"}],"database_specific":{"extracted_events":[{"introduced":"4.0.8"},{"last_affected":"4.0.8"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:libtiff:libtiff:4.0.8:*:*:*:*:*:*:*"}}],"versions":["4.0.8","Release-v4-0-8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16232.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/libtiff/libtiff","events":[{"introduced":"84e1f1b66df4c91951cfc17556d5228d0d3e5c9f"},{"last_affected":"84e1f1b66df4c91951cfc17556d5228d0d3e5c9f"}],"database_specific":{"extracted_events":[{"introduced":"4.0.8"},{"last_affected":"4.0.8"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:libtiff:libtiff:4.0.8:*:*:*:*:*:*:*"}}],"versions":["4.0.8","v4.0.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16232.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}