Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3632

Опубликовано: 21 сент. 2016
Источник: debian
EPSS Низкий

Описание

The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • src:tiff3: built binary packages do not contain the TIFF tools

  • http://bugzilla.maptools.org/show_bug.cgi?id=2549

  • Upstream will remove thumbnail from 4.0.7 release

  • No patch available. Issue marked as wontfix by upstream.

  • thumbnail(1) was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

EPSS

Процентиль: 40%
0.00184
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.

CVSS3: 5.3
redhat
больше 9 лет назад

The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.

CVSS3: 7.8
nvd
почти 9 лет назад

The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.

CVSS3: 7.8
github
больше 3 лет назад

The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.

suse-cvrf
около 7 лет назад

Security update for tiff

EPSS

Процентиль: 40%
0.00184
Низкий