Описание
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:libtiff:libtiff:4.0.9:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00459
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-476
Связанные уязвимости
CVSS3: 6.5
ubuntu
почти 8 лет назад
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.
CVSS3: 3.3
redhat
почти 8 лет назад
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.
CVSS3: 6.5
debian
почти 8 лет назад
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other pr ...
CVSS3: 6.5
github
больше 3 лет назад
LibTIFF 4.0.9 has a NULL pointer dereference in the jpeg_fdct_16x16 function in jfdctint.c.
EPSS
Процентиль: 64%
0.00459
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-476