Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11459

Опубликовано: 13 апр. 2019
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

Отчет

This issue affects the versions of evince as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5evinceOut of support scope
Red Hat Enterprise Linux 6evinceOut of support scope
Red Hat Enterprise Linux 7evinceFixedRHSA-2020:107431.03.2020
Red Hat Enterprise Linux 7popplerFixedRHSA-2020:107431.03.2020
Red Hat Enterprise Linux 8accountsserviceFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8appstream-dataFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8baobabFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8chrome-gnome-shellFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8evinceFixedRHSA-2019:355305.11.2019
Red Hat Enterprise Linux 8file-rollerFixedRHSA-2019:355305.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1716295evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail()

EPSS

Процентиль: 63%
0.00458
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVSS3: 5.5
nvd
около 6 лет назад

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVSS3: 5.5
debian
около 6 лет назад

The tiff_document_render() and tiff_document_get_thumbnail() functions ...

suse-cvrf
почти 6 лет назад

Recommended update for evince

suse-cvrf
почти 6 лет назад

Recommended update for evince

EPSS

Процентиль: 63%
0.00458
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2019-11459