Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14973

Опубликовано: 14 авг. 2019
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffOut of support scope
Red Hat Enterprise Linux 6libtiffWill not fix
Red Hat Enterprise Linux 7libtiffFixedRHSA-2020:390229.09.2020
Red Hat Enterprise Linux 8libtiffFixedRHSA-2020:168828.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1745951libtiff: integer overflow in _TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c

EPSS

Процентиль: 74%
0.00833
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

CVSS3: 6.5
nvd
около 6 лет назад

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

CVSS3: 6.5
debian
около 6 лет назад

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through ...

suse-cvrf
почти 5 лет назад

Security update for tiff

suse-cvrf
почти 5 лет назад

Security update for tiff

EPSS

Процентиль: 74%
0.00833
Низкий

4.5 Medium

CVSS3