Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6223

Опубликовано: 10 июл. 2016
Источник: redhat
CVSS3: 6.5
CVSS2: 5.8
EPSS Низкий

Описание

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 6libtiffNot affected
Red Hat Enterprise Linux 7compat-libtiff3Not affected
Red Hat Enterprise Linux 7libtiffWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1356867libtiff: Out-of-bounds read on memory-mapped files in TIFFReadRawStrip1() and TIFFReadRawTile1()

EPSS

Процентиль: 79%
0.01239
Низкий

6.5 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

CVSS3: 9.1
nvd
около 9 лет назад

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

CVSS3: 9.1
debian
около 9 лет назад

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in ...

CVSS3: 9.1
github
больше 3 лет назад

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

suse-cvrf
около 7 лет назад

Security update for tiff

EPSS

Процентиль: 79%
0.01239
Низкий

6.5 Medium

CVSS3

5.8 Medium

CVSS2