Описание
An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.
Ссылки
- Broken LinkThird Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- ExploitNot ApplicableThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- ExploitNot ApplicableThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:canvasgfx:canvas_draw:5.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00562
Низкий
8.8 High
CVSS3
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-787
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.
EPSS
Процентиль: 68%
0.00562
Низкий
8.8 High
CVSS3
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-787