Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-3620

Опубликовано: 03 окт. 2016
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
Версия до 4.0.6 (включая)

EPSS

Процентиль: 87%
0.03205
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

redhat
больше 10 лет назад

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

CVSS3: 7.5
debian
почти 10 лет назад

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4. ...

CVSS3: 7.5
github
больше 4 лет назад

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

suse-cvrf
больше 7 лет назад

Security update for tiff

EPSS

Процентиль: 87%
0.03205
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-125