Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8130

Опубликовано: 12 мар. 2018
Источник: debian
EPSS Низкий

Описание

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.5-1package
tiff3not-affectedpackage

Примечания

  • Advisory: http://www.conostix.com/pub/adv/CVE-2014-8130-LibTIFF-Division_By_Zero.txt

  • http://bugzilla.maptools.org/show_bug.cgi?id=2483

  • Crash in a frontend tool w/o potential for code injection, marked as unimportant

EPSS

Процентиль: 83%
0.02075
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

CVSS3: 3.3
redhat
почти 11 лет назад

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

CVSS3: 6.5
nvd
больше 7 лет назад

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

CVSS3: 6.5
github
больше 3 лет назад

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

suse-cvrf
около 10 лет назад

Security update for tiff

EPSS

Процентиль: 83%
0.02075
Низкий