Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17546

Опубликовано: 14 окт. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
Версия до 4.1.0 (исключая)
Конфигурация 2
cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
Версия до 3.0.1 (включая)

EPSS

Процентиль: 59%
0.00373
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
redhat
больше 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
debian
больше 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0. ...

rocky
больше 5 лет назад

Moderate: libtiff security update

CVSS3: 8.8
github
больше 3 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

EPSS

Процентиль: 59%
0.00373
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-190