Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-5022

Опубликовано: 09 фев. 2009
Источник: redhat
CVSS2: 6.8

Описание

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

Отчет

This flaw did not affect libtiff as shipped in Red Hat Enterprise Linux 4 or 5. The OJPEG decoder is disabled in those distributions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4libtiffNot affected
Red Hat Enterprise Linux 5libtiffNot affected
Red Hat Enterprise Linux 6libtiffFixedRHSA-2011:045218.04.2011

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-119

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

nvd
около 14 лет назад

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

debian
около 14 лет назад

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibT ...

github
около 3 лет назад

Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

oracle-oval
около 14 лет назад

ELSA-2011-0452: libtiff security update (IMPORTANT)

6.8 Medium

CVSS2