Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v898-4vh8-7f99

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.

In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.

EPSS

Процентиль: 25%
0.00087
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4
ubuntu
больше 8 лет назад

In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).

CVSS3: 3.3
redhat
почти 9 лет назад

In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).

CVSS3: 4
nvd
больше 8 лет назад

In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).

CVSS3: 4
debian
больше 8 лет назад

In LibTIFF 4.0.6 and possibly other versions, the program processes BM ...

fstec
больше 8 лет назад

Уязвимость компонента bmp2tiff библиотеки LibTIFF, позволяющая нарушителю получить доступ на чтение данных за границами буфера, выделенного в динамической памяти

EPSS

Процентиль: 25%
0.00087
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-125