Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qchv-v695-4m9x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

EPSS

Процентиль: 72%
0.01483
Низкий

7.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

CVSS3: 4.4
redhat
почти 8 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

CVSS3: 7.1
nvd
больше 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

CVSS3: 7.1
debian
больше 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could ...

suse-cvrf
больше 4 лет назад

Security update for dcraw

EPSS

Процентиль: 72%
0.01483
Низкий

7.1 High

CVSS3

Дефекты

CWE-125