Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-18768

Опубликовано: 20 мар. 2019
Источник: redhat
CVSS3: 5.5

Описание

There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.

A heap-based buffer overflow exists in libtiff in TIFFmemcpy. This flaw allows an attacker to craft a specific TIFF file, possibly causing a denial of service that results in a loss of the system’s availability.

Отчет

Red Hat has determined that this vulnerability is of low impact as successful exploitation relies on convincing a user to manually open a malicious file with tiffcp and bypassing security mechanisms such ASLR.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Out of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8compat-libtiff3Will not fix
Red Hat Enterprise Linux 8libtiffWill not fix
Red Hat Enterprise Linux 9libtiffNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2235458libtiff: heap-based buffer overflow in _TIFFmemcpy() in tif_unix.c

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.

CVSS3: 5.5
nvd
больше 2 лет назад

There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.

CVSS3: 5.5
debian
больше 2 лет назад

There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in ...

CVSS3: 5.5
github
больше 2 лет назад

There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.

CVSS3: 5.5
fstec
больше 2 лет назад

Уязвимость функции _TIFFmemcpy (tif_unix.с) библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3