Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-1916

Опубликовано: 10 апр. 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.5.0 (включая)

EPSS

Процентиль: 31%
0.00388
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
redhat
больше 3 лет назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.1
debian
больше 3 лет назад

A flaw was found in tiffcrop, a program distributed by the libtiff pac ...

CVSS3: 6.1
github
больше 3 лет назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

EPSS

Процентиль: 31%
0.00388
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125
CWE-125