Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5563

Опубликовано: 23 янв. 2017
Источник: debian

Описание

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.7-1package

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2664

  • bmp2tiff utility removed in 4.0.6-3 and 4.0.3-12.3+deb8u2

  • Removed upstream in https://gitlab.com/libtiff/libtiff/-/commit/30366c9f226593f37623bfd235274aeac1e575ad (v4.0.7)

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 9 лет назад

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.

CVSS3: 5.3
redhat
около 9 лет назад

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.

CVSS3: 8.8
nvd
около 9 лет назад

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.

CVSS3: 8.8
github
больше 3 лет назад

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.