Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9330

Опубликовано: 22 дек. 2014
Источник: redhat
CVSS3: 3.3
CVSS2: 4.3
EPSS Низкий

Описание

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.

A flaw was discovered in the bmp2tiff utility. By tricking a user into processing a specially crafted file, a remote attacker could exploit this flaw to cause a crash or memory corruption and, possibly, execute arbitrary code with the privileges of the user running the libtiff tool.

Отчет

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libtiff.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 6libtiffFixedRHSA-2016:154702.08.2016
Red Hat Enterprise Linux 7libtiffFixedRHSA-2016:154602.08.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1177893libtiff: Out-of-bounds reads followed by a crash in bmp2tiff

EPSS

Процентиль: 78%
0.01171
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.

nvd
больше 10 лет назад

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.

debian
больше 10 лет назад

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows ...

github
больше 3 лет назад

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.

oracle-oval
около 9 лет назад

ELSA-2016-1547: libtiff security update (IMPORTANT)

EPSS

Процентиль: 78%
0.01171
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Уязвимость CVE-2014-9330