Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1167

Опубликовано: 21 мар. 2011
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=684939libtiff: heap-based buffer overflow in thunder decoder (ZDI-11-107)

EPSS

Процентиль: 87%
0.03438
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.

nvd
около 14 лет назад

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.

debian
около 14 лет назад

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in ...

github
около 3 лет назад

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.

oracle-oval
около 14 лет назад

ELSA-2011-0392: libtiff security and bug fix update (IMPORTANT)

EPSS

Процентиль: 87%
0.03438
Низкий

6.8 Medium

CVSS2