Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3186

Опубликовано: 19 апр. 2016
Источник: debian
EPSS Низкий

Описание

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1319666

  • https://bugzilla.redhat.com/show_bug.cgi?id=1319503

  • http://bugzilla.maptools.org/show_bug.cgi?id=2536

  • Proposed patch from Red Hat: https://bugzilla.redhat.com/attachment.cgi?id=1144235&action=diff

  • gif2tiff was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

EPSS

Процентиль: 73%
0.00766
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
почти 10 лет назад

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

redhat
почти 10 лет назад

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

CVSS3: 6.2
nvd
почти 10 лет назад

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

CVSS3: 6.2
github
больше 3 лет назад

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

suse-cvrf
больше 9 лет назад

Security update for tiff

EPSS

Процентиль: 73%
0.00766
Низкий