Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5318

Опубликовано: 20 янв. 2017
Источник: debian
EPSS Низкий

Описание

Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage

Примечания

  • thumbnail(1) was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

  • _TIFFVGetField isn't specific to thumbnail tool, there's http://bugzilla.maptools.org/show_bug.cgi?id=2580 to enhance that,

  • but treating this bug (as related to thumbmail) as fixed.

  • http://bugzilla.maptools.org/show_bug.cgi?id=2561

  • This seems a duplicate of CVE-2015-7554 ( http://bugzilla.maptools.org/show_bug.cgi?id=2564 ). At the very least, a generic fix for CVE-2015-7554 would also fix this one as the illegal write is at the exact same location in the code.

  • Reproducer file here: http://bugzilla.maptools.org/attachment.cgi?id=671

  • With 4.0.6-2 (sid), I get a segfault.

  • With 4.0.3-12.3+deb8u1 (jessie), I get a segfault.

  • With 3.9.6-11+deb7u1 (wheezy), I get a failure: MissingRequired: ../CVE-2016-5318.tiff: TIFF directory is missing required "StripOffsets" field.

EPSS

Процентиль: 75%
0.00879
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

redhat
почти 10 лет назад

Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

CVSS3: 6.5
nvd
около 9 лет назад

Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

CVSS3: 6.5
github
больше 3 лет назад

Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

fstec
около 9 лет назад

Уязвимость библиотеки LibTIFF, позволяющая нарушителю получить несанкционированный доступ к устройству

EPSS

Процентиль: 75%
0.00879
Низкий