Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-7554

Опубликовано: 08 янв. 2016
Источник: debian
EPSS Низкий

Описание

The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.7-7package
tifffixed4.0.3-12.3+deb8u4jessiepackage
tiff3removedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2015/12/26/7

  • SUSE seem to have a fix (disputed): https://bugzilla.suse.com/show_bug.cgi?id=960341

  • Reproducer file here: https://bugzilla.suse.com/attachment.cgi?id=665389

  • http://bugzilla.maptools.org/show_bug.cgi?id=2564

  • partially fixed by http://bugzilla.maptools.org/show_bug.cgi?id=2564#c2

  • --

  • The problem is present in tiff3 3.9.6-11+deb7u1 on wheezy (the problematic code

  • gets executed under gdb), however for some reason this does not lead to a segfault.

EPSS

Процентиль: 65%
0.00499
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.

CVSS3: 5.3
redhat
больше 9 лет назад

The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.

CVSS3: 9.8
nvd
больше 9 лет назад

The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.

suse-cvrf
больше 9 лет назад

Security update for tiff

suse-cvrf
больше 9 лет назад

Security update for tiff

EPSS

Процентиль: 65%
0.00499
Низкий