Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3634

Опубликовано: 03 окт. 2016
Источник: debian

Описание

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • src:tiff3: built binary packages do not contain the TIFF tools

  • http://bugzilla.maptools.org/show_bug.cgi?id=2547

  • Upstream will remove thumbnail from 4.0.7 release

  • No patch available. Issue marked as wontfix by upstream.

  • thumbnail(1) was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

redhat
больше 9 лет назад

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

CVSS3: 7.5
nvd
около 9 лет назад

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

CVSS3: 7.5
github
больше 3 лет назад

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

fstec
около 9 лет назад

Уязвимость библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании