Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-7186

Опубликовано: 16 фев. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 9.8

Описание

Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.75.3-2
cosmic

not-affected

1.75.3-2
devel

not-affected

1.75.3-2
disco

not-affected

1.75.3-2
eoan

not-affected

1.75.3-2
esm-apps/bionic

not-affected

1.75.3-2
esm-apps/focal

not-affected

1.75.3-2
esm-apps/jammy

not-affected

1.75.3-2
esm-apps/xenial

released

1.73-1ubuntu0.1~esm1

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 8 лет назад

Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.

CVSS3: 9.8
debian
почти 8 лет назад

Leptonica before 1.75.3 does not limit the number of characters in a % ...

CVSS3: 9.8
github
больше 3 лет назад

Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.

CVSS3: 9.8
fstec
почти 8 лет назад

Уязвимость функций gplotRead и ptaReadStream библиотеки для работы с изображениями Leptonica, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

suse-cvrf
почти 8 лет назад

Security update for leptonica

7.5 High

CVSS2

9.8 Critical

CVSS3