Описание
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | libtiff | Will not fix | ||
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Will not fix | ||
| Red Hat Enterprise Linux 6 | libtiff | Fixed | RHSA-2017:0225 | 01.02.2017 |
| Red Hat Enterprise Linux 7 | libtiff | Fixed | RHSA-2017:0225 | 01.02.2017 |
Показывать по
Дополнительная информация
Статус:
4.4 Medium
CVSS3
5.8 Medium
CVSS2
Связанные уязвимости
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows re ...
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.
4.4 Medium
CVSS3
5.8 Medium
CVSS2