Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1916

Опубликовано: 10 апр. 2023
Источник: debian

Описание

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.7.0-1package

Примечания

  • https://gitlab.com/libtiff/libtiff/-/issues/536

  • https://gitlab.com/libtiff/libtiff/-/issues/537

  • https://gitlab.com/libtiff/libtiff/-/merge_requests/595

  • Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/a20298c4785c369469510613dfbc5bf230164fed (v4.7.0rc1)

  • Crash in CLI tool, no security impact

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
redhat
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
nvd
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.1
github
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.