Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qchv-v695-4m9x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

EPSS

Процентиль: 42%
0.00201
Низкий

7.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

CVSS3: 4.4
redhat
около 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

CVSS3: 7.1
nvd
около 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

CVSS3: 7.1
debian
около 7 лет назад

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could ...

suse-cvrf
больше 3 лет назад

Security update for dcraw

EPSS

Процентиль: 42%
0.00201
Низкий

7.1 High

CVSS3

Дефекты

CWE-125