CVE Vulnerabilities

CVE-2017-6314

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 10, 2017 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW

The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Gdk-pixbuf Gnome * 2.36.12 (excluding)
Gdk-pixbuf Ubuntu artful *
Gdk-pixbuf Ubuntu precise *
Gdk-pixbuf Ubuntu trusty *
Gdk-pixbuf Ubuntu upstream *
Gdk-pixbuf Ubuntu vivid/stable-phone-overlay *
Gdk-pixbuf Ubuntu xenial *
Gdk-pixbuf Ubuntu yakkety *
Gdk-pixbuf Ubuntu zesty *

References