Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5784

Опубликовано: 19 янв. 2018
Источник: debian
EPSS Низкий

Описание

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.0.9-4package
tiff3removedpackage
tiff3postponedwheezypackage

Примечания

  • http://bugzilla.maptools.org/show_bug.cgi?id=2772

  • Fixed by: https://gitlab.com/libtiff/libtiff/commit/473851d211cf8805a161820337ca74cc9615d6ef

EPSS

Процентиль: 52%
0.00285
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

CVSS3: 3.3
redhat
около 8 лет назад

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

CVSS3: 6.5
nvd
около 8 лет назад

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

CVSS3: 6.5
github
больше 3 лет назад

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.

CVSS3: 6.5
fstec
около 8 лет назад

Уязвимость функции TIFFSetDirectory библиотеки LibTIFF, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.00285
Низкий