Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-3164

Опубликовано: 02 нояб. 2023
Источник: debian
EPSS Низкий

Описание

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.7.0-1package

Примечания

  • https://gitlab.com/libtiff/libtiff/-/issues/542

  • https://gitlab.com/libtiff/libtiff/-/merge_requests/595

  • Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/a20298c4785c369469510613dfbc5bf230164fed (v4.7.0rc1)

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 1%
0.0001
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.

CVSS3: 5.5
redhat
больше 2 лет назад

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.

CVSS3: 5.5
nvd
около 2 лет назад

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.

CVSS3: 5.5
msrc
10 месяцев назад

Описание отсутствует

suse-cvrf
больше 1 года назад

Security update for tiff

EPSS

Процентиль: 1%
0.0001
Низкий