Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8129

Опубликовано: 07 дек. 2014
Источник: redhat
CVSS3: 4.4
CVSS2: 3.6

Описание

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.

Отчет

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 6libtiffFixedRHSA-2016:154702.08.2016
Red Hat Enterprise Linux 7libtiffFixedRHSA-2016:154602.08.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1185815libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf

4.4 Medium

CVSS3

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.

CVSS3: 8.8
nvd
больше 7 лет назад

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.

CVSS3: 8.8
debian
больше 7 лет назад

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (ou ...

CVSS3: 8.8
github
больше 3 лет назад

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.

suse-cvrf
около 10 лет назад

Security update for tiff

4.4 Medium

CVSS3

3.6 Low

CVSS2