Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10779

Опубликовано: 07 мая 2018
Источник: debian

Описание

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tifffixed4.0.3-12.3+deb8u2jessiepackage
tiff3removedpackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2788

  • Utility bmp2tiff has been removed from upstream LibTIFF

  • bmp2tiff was removed in 4.0.6-3 and DSA 3762, marking as fixed although

  • technically still present in the source package

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

CVSS3: 5.3
redhat
почти 8 лет назад

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

CVSS3: 6.5
nvd
почти 8 лет назад

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

CVSS3: 6.5
github
больше 3 лет назад

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

CVSS3: 6.5
fstec
почти 8 лет назад

Уязвимость функции TIFFWriteScanline библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании