Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17546

Опубликовано: 14 окт. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
Версия до 4.1.0 (исключая)
Конфигурация 2
cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
Версия до 3.0.1 (включая)

EPSS

Процентиль: 58%
0.00373
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
redhat
около 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
debian
почти 6 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0. ...

CVSS3: 8.8
github
около 3 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

oracle-oval
почти 5 лет назад

ELSA-2020-4634: libtiff security update (MODERATE)

EPSS

Процентиль: 58%
0.00373
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-190