Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5360

Опубликовано: 14 янв. 2018
Источник: debian

Описание

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.6-3package
tiffno-dsajessiepackage
tiff3undeterminedpackage
tiff3postponedwheezypackage

Примечания

  • Issue demostrated in tiff via a vector through graphicsmagick, cf.

  • https://sourceforge.net/p/graphicsmagick/bugs/540/

  • Same issue as http://bugzilla.maptools.org/show_bug.cgi?id=2500 (CVE-2014-8127)

  • fixed as per 2016-10-25 (first release to ship the patch seems to be 4.0.7)

  • https://gitlab.com/libtiff/libtiff/commit/739dcd28a061738b317c1e9f91029d9cbc157159

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

CVSS3: 3.3
redhat
около 8 лет назад

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

CVSS3: 8.8
nvd
около 8 лет назад

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

CVSS3: 8.8
github
больше 3 лет назад

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.