Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-17795

Опубликовано: 30 сент. 2018
Источник: debian
EPSS Низкий

Описание

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.9-2package
tifffixed4.0.8-2+deb9u2stretchpackage
tifffixed4.0.3-12.3+deb8u5jessiepackage
tiff3removedpackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2816

  • Similar issue as CVE-2017-9935 but not considered the same, but adressed

  • with same commit.

  • https://gitlab.com/libtiff/libtiff/commit/3dd8f6a357981a4090f126ab9025056c938b6940

EPSS

Процентиль: 79%
0.01251
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

CVSS3: 4.3
redhat
больше 7 лет назад

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

CVSS3: 8.8
nvd
больше 7 лет назад

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

CVSS3: 8.8
github
больше 3 лет назад

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость функции t2p_write_pdf библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 79%
0.01251
Низкий