Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9453

Опубликовано: 27 янв. 2017
Источник: debian

Описание

The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.2-6+deb7u7wheezypackage
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • CVE-2016-9453 for wheezy fixed via CVE-2016-5652

  • http://bugzilla.maptools.org/show_bug.cgi?id=2579

  • https://github.com/vadz/libtiff/commit/d2955714a4a0b8ca10941550cfbf64c7e111fbf1

  • For unstable this fix was included in the fix for TALOS-CAN-0187 / CVE-2016-5652

  • and included in patches/09-CVE-2016-5652.patch

  • Problem not reproducible in wheezy with 4.0.2-6+deb7u7, in jessie with 4.0.3-12.3+deb8u1, in both cases I get this output (but no segfault or error with valgrind):

  • TIFFReadDirectoryCheckOrder: Warning, Invalid TIFF directory; tags are not sorted in ascending order.

  • TIFFReadDirectory: Warning, Unknown field with tag 1 (0x1) encountered.

  • TIFFReadDirectory: Warning, Unknown field with tag 3 (0x3) encountered.

  • TIFFReadDirectory: IO error during reading of "BitsPerSample".

  • tiff2pdf: Can't open input file ./CVE-2016-9453.tiff for reading.

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.

CVSS3: 7.8
redhat
около 9 лет назад

The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.

CVSS3: 7.8
nvd
около 9 лет назад

The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.

CVSS3: 7.8
github
больше 3 лет назад

The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.

suse-cvrf
около 9 лет назад

Security update for tiff