Описание
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
Ссылки
- ExploitIssue TrackingPatch
- ExploitIssue TrackingPatch
Уязвимые конфигурации
Конфигурация 1Версия до 4.5.0 (включая)
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00008
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-787
CWE-787
Связанные уязвимости
CVSS3: 5.5
ubuntu
около 2 лет назад
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
CVSS3: 5.5
redhat
около 2 лет назад
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
CVSS3: 5.5
debian
около 2 лет назад
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-ba ...
CVSS3: 8.8
github
около 2 лет назад
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
EPSS
Процентиль: 0%
0.00008
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-787
CWE-787