Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-3621

Опубликовано: 03 окт. 2016
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

РелизСтатусПримечание
artful

not-affected

4.0.7-1
devel

not-affected

4.0.7-1
esm-infra-legacy/trusty

ignored

esm-infra/xenial

ignored

precise

ignored

end of life
precise/esm

ignored

trusty

ignored

trusty/esm

ignored

upstream

released

4.0.6-3
vivid/stable-phone-overlay

ignored

end of life

Показывать по

EPSS

Процентиль: 71%
0.00676
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

redhat
почти 10 лет назад

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

CVSS3: 8.8
nvd
больше 9 лет назад

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

CVSS3: 8.8
debian
больше 9 лет назад

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4. ...

CVSS3: 8.8
github
больше 3 лет назад

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.

suse-cvrf
около 7 лет назад

Security update for tiff

EPSS

Процентиль: 71%
0.00676
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3