Описание
LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
tiff | fixed | 4.0.7-1 | package | |
tiff | ignored | jessie | package | |
tiff | not-affected | wheezy | package | |
tiff | not-affected | squeeze | package | |
tiff3 | removed | package | ||
tiff3 | not-affected | wheezy | package |
Примечания
Test file here: https://marc.info/?l=oss-security&m=144284777006804&q=p6
Reproduce with "ltrace -e realloc tiffdither /tmp/oom.tif /dev/null"
at the end you see "libtiff.so.5->realloc(0, 1636178024)"
EPSS
Связанные уязвимости
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
EPSS