Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-1916

Опубликовано: 10 апр. 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.5.0 (включая)

EPSS

Процентиль: 4%
0.00018
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
redhat
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS3: 6.1
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.1
debian
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff pac ...

CVSS3: 6.1
github
почти 3 года назад

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

EPSS

Процентиль: 4%
0.00018
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125
CWE-125