Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6128

Опубликовано: 04 янв. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

A vulnerability was found in LibTIFF, where a memory leak in the TIFFFdOpen function within tif_unix.c could lead to a denial of service, where a remote attacker could exploit this flaw by tricking a user into opening a specially crafted file, causing increased memory consumption and potential application instability over time.

Отчет

This vulnerability is rated as moderate because a memory leak in LibTIFF’s TIFFFdOpen function within tif_unix.c could lead to a denial of service, exploitation requires user interaction, as an attacker must persuade a victim to open a specially crafted file. While this does not lead to code execution, repeated exploitation could impact application availability.

Меры по смягчению последствий

This bug could be mitigated by configuring process memory limits using cgroups.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 6libtiffWill not fix
Red Hat Enterprise Linux 7libtiffWill not fix
Red Hat Enterprise Linux 8libtiffWill not fix
Red Hat Enterprise Linux 8mingw-libtiffWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-244
https://bugzilla.redhat.com/show_bug.cgi?id=1667122libtiff: memory leak in TIFFFdOpen function in tif_unix.c when using pal2rgb

EPSS

Процентиль: 89%
0.03869
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

CVSS3: 8.8
nvd
больше 7 лет назад

The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

CVSS3: 8.8
debian
больше 7 лет назад

The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory l ...

CVSS3: 8.8
github
больше 4 лет назад

The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

suse-cvrf
больше 7 лет назад

Security update for tiff

EPSS

Процентиль: 89%
0.03869
Низкий

6.5 Medium

CVSS3