Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-17095

Опубликовано: 02 дек. 2017
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

РелизСтатусПримечание
artful

released

4.0.8-5ubuntu0.1
devel

released

4.0.9-4ubuntu1
esm-infra-legacy/trusty

not-affected

4.0.3-7ubuntu0.9
esm-infra/xenial

not-affected

4.0.6-1ubuntu0.4
precise/esm

ignored

trusty

released

4.0.3-7ubuntu0.9
trusty/esm

not-affected

4.0.3-7ubuntu0.9
upstream

needs-triage

xenial

released

4.0.6-1ubuntu0.4
zesty

ignored

end of life

Показывать по

EPSS

Процентиль: 83%
0.01914
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

CVSS3: 8.8
nvd
больше 7 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

CVSS3: 8.8
debian
больше 7 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to ...

rocky
10 дней назад

Moderate: libtiff security update

CVSS3: 8.8
github
около 3 лет назад

tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

EPSS

Процентиль: 83%
0.01914
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3