Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5102

Опубликовано: 06 фев. 2017
Источник: debian

Описание

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2552

  • confirmed this still crashes with latest CVS, version v4.0.6

  • also confirmed this crashes v4.0.2 in wheezy

  • Upstream will remove gif2tiff from 4.0.7 release

  • No patch available. Marked as wontfix by upstream

  • Reproducer http://bugs.fi/media/afl/libtiff/CVE-2016-5102.gif

  • gif2tiff was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

redhat
больше 9 лет назад

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

CVSS3: 5.5
nvd
около 9 лет назад

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

CVSS3: 5.5
github
больше 3 лет назад

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

suse-cvrf
почти 7 лет назад

Security update for tiff