Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-19131

Опубликовано: 07 сент. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

The libtiff package is susceptible to a heap/buffer overflow via the "invertImage()" which may lead to a DoS. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Not affected
Red Hat Enterprise Linux 7libtiffWill not fix
Red Hat Enterprise Linux 8compat-libtiff3Not affected
Red Hat Enterprise Linux 8mingw-libtiffWill not fix
Red Hat Enterprise Linux 9libtiffNot affected
Red Hat Enterprise Linux 8libtiffFixedRHSA-2022:181010.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2004031libtiff: a buffer overflow via the "invertImage()" may lead to DoS

EPSS

Процентиль: 64%
0.00483
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

CVSS3: 7.5
nvd
почти 4 года назад

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

CVSS3: 7.5
debian
почти 4 года назад

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial ...

rocky
около 3 лет назад

Moderate: libtiff security update

github
около 3 лет назад

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

EPSS

Процентиль: 64%
0.00483
Низкий

7.5 High

CVSS3