Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8870

Опубликовано: 28 янв. 2015
Источник: redhat
CVSS3: 4.4
CVSS2: 5.8

Описание

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 7compat-libtiff3Will not fix
Red Hat Enterprise Linux 6libtiffFixedRHSA-2017:022501.02.2017
Red Hat Enterprise Linux 7libtiffFixedRHSA-2017:022501.02.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1402778libtiff: Integer overflow in tools/bmp2tiff.c

4.4 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 9 лет назад

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.

CVSS3: 7.4
nvd
почти 9 лет назад

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.

CVSS3: 7.4
debian
почти 9 лет назад

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows re ...

CVSS3: 7.4
github
больше 3 лет назад

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.

oracle-oval
почти 9 лет назад

ELSA-2017-0225: libtiff security update (MODERATE)

4.4 Medium

CVSS3

5.8 Medium

CVSS2