Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0891

Опубликовано: 22 фев. 2022
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

Отчет

The severity of this flaw was changed to Low because it is an out-of-bounds read of 1 byte and in the tiffcrop tool rather than in the library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Out of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8compat-libtiff3Fix deferred
Red Hat Enterprise Linux 8mingw-libtiffFix deferred
Red Hat Enterprise Linux 8libtiffFixedRHSA-2022:758508.11.2022
Red Hat Enterprise Linux 9libtiffFixedRHSA-2022:819415.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2064411libtiff: heap buffer overflow in extractImageSection

EPSS

Процентиль: 5%
0.00024
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVSS3: 6.1
nvd
больше 3 лет назад

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVSS3: 7.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.1
debian
больше 3 лет назад

A heap buffer overflow in ExtractImageSection function in tiffcrop.c i ...

CVSS3: 7.1
github
больше 3 лет назад

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

EPSS

Процентиль: 5%
0.00024
Низкий

6.1 Medium

CVSS3