Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9532

Опубликовано: 06 фев. 2017
Источник: debian
EPSS Низкий

Описание

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.7-1package
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2592

  • Patch: https://github.com/vadz/libtiff/commit/21d39de1002a5e69caa0574b2cc05d795d6fbfad

  • https://www.openwall.com/lists/oss-security/2016/11/11/14

EPSS

Процентиль: 69%
0.00612
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

CVSS3: 3.3
redhat
около 9 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

CVSS3: 5.5
nvd
около 9 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

EPSS

Процентиль: 69%
0.00612
Низкий