Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7602

Опубликовано: 09 апр. 2017
Источник: debian
EPSS Низкий

Описание

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.7-6package
tiff3removedpackage
tiff3not-affectedwheezypackage

Примечания

  • https://github.com/vadz/libtiff/commit/66e7bd59520996740e4df5495a830b42fae48bc4

  • https://blogs.gentoo.org/ago/2017/04/01/libtiff-multiple-ubsan-crashes

EPSS

Процентиль: 66%
0.00515
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

CVSS3: 3.3
redhat
почти 9 лет назад

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

CVSS3: 7.8
nvd
почти 9 лет назад

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

CVSS3: 7.8
github
больше 3 лет назад

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

suse-cvrf
больше 8 лет назад

Security update for tiff

EPSS

Процентиль: 66%
0.00515
Низкий
Уязвимость CVE-2017-7602