Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9532

Опубликовано: 06 фев. 2017
Источник: debian

Описание

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.7-1package
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2592

  • Patch: https://github.com/vadz/libtiff/commit/21d39de1002a5e69caa0574b2cc05d795d6fbfad

  • https://www.openwall.com/lists/oss-security/2016/11/11/14

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

CVSS3: 3.3
redhat
почти 10 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

CVSS3: 5.5
nvd
больше 9 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

CVSS3: 5.5
github
больше 4 лет назад

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.