Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17546

Опубликовано: 14 окт. 2019
Источник: debian
EPSS Низкий

Описание

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gdalfixed3.1.0+dfsg-1package
tifffixed4.0.10+git190818-1package

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443

  • https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf (v3.1.0RC1)

  • https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145 (v4.1.0)

  • gdal uses system libtiff libraries since 2.0.1+dfsg-1~exp1 (#684233)

EPSS

Процентиль: 59%
0.00373
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
redhat
больше 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
nvd
больше 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

rocky
больше 5 лет назад

Moderate: libtiff security update

CVSS3: 8.8
github
больше 3 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

EPSS

Процентиль: 59%
0.00373
Низкий