Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8331

Опубликовано: 28 окт. 2016
Источник: debian
EPSS Низкий

Описание

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • http://www.talosintelligence.com/reports/TALOS-2016-0190/

  • thumbnail(1) was removed in 4.0.6-3 and DSA 3762, marking as fixed although technically still present in the source package

  • From the backtrace shared in the report, we can see that the crash is triggered though the thumbnail tool which has been dropped upstream.

EPSS

Процентиль: 91%
0.07325
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 9 лет назад

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

CVSS3: 8.1
redhat
больше 9 лет назад

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

CVSS3: 8.1
nvd
больше 9 лет назад

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

CVSS3: 8.1
github
больше 3 лет назад

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

suse-cvrf
больше 7 лет назад

Security update for tiff

EPSS

Процентиль: 91%
0.07325
Низкий