Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5319

Опубликовано: 20 янв. 2017
Источник: debian

Описание

Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2562

  • Reproducer http://bugzilla.maptools.org/attachment.cgi?id=652

  • Utility bmp2tiff has been removed from upstream LibTIFF

  • No patch available. Marked as wontfix by upstream.

  • bmp2tiff was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

redhat
почти 10 лет назад

Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

CVSS3: 6.5
nvd
около 9 лет назад

Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

CVSS3: 6.5
github
больше 3 лет назад

Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

fstec
около 9 лет назад

Уязвимость библиотеки LibTIFF, позволяющая нарушителю вызвать аварийное завершение работы приложения