Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11459

Опубликовано: 22 апр. 2019
Источник: debian
EPSS Низкий

Описание

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
atrilfixed1.22.3-1package
atrilfixed1.20.3-1+deb10u1busterpackage
atrilfixed1.16.1-2+deb9u2stretchpackage
evincefixed3.32.0-3package
evincefixed3.30.2-3+deb10u1busterpackage

Примечания

  • https://gitlab.gnome.org/GNOME/evince/issues/1129

  • Fixed by: https://gitlab.gnome.org/GNOME/evince/commit/3e38d5ad724a042eebadcba8c2d57b0f48b7a8c7

  • Negligible security impact

EPSS

Процентиль: 63%
0.00458
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVSS3: 3.3
redhat
около 6 лет назад

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVSS3: 5.5
nvd
около 6 лет назад

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

suse-cvrf
почти 6 лет назад

Recommended update for evince

suse-cvrf
почти 6 лет назад

Recommended update for evince

EPSS

Процентиль: 63%
0.00458
Низкий