Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-6277

Опубликовано: 24 нояб. 2023
Источник: debian
EPSS Низкий

Описание

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.5.1+git230720-2package
tiffignoredbookwormpackage
tiffignoredbullseyepackage
tiffignoredbusterpackage

Примечания

  • https://gitlab.com/libtiff/libtiff/-/issues/614

  • https://gitlab.com/libtiff/libtiff/-/merge_requests/545

  • https://gitlab.com/libtiff/libtiff/-/commit/5320c9d89c054fa805d037d84c57da874470b01a

  • Updating with fix for CVE-2023-6277 will cause a regression in libimager-perl, cf.

  • https://bugs.debian.org/1057270

EPSS

Процентиль: 61%
0.00418
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

CVSS3: 6.5
redhat
около 2 лет назад

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

CVSS3: 6.5
nvd
около 2 лет назад

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

CVSS3: 6.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
github
около 2 лет назад

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

EPSS

Процентиль: 61%
0.00418
Низкий