Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-7663

Опубликовано: 09 фев. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.5

Описание

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

uses system libtiff
cosmic

not-affected

uses system libtiff
devel

not-affected

uses system libtiff
disco

not-affected

uses system libtiff
eoan

not-affected

uses system libtiff
esm-apps/bionic

not-affected

uses system libtiff
esm-apps/focal

not-affected

uses system libtiff
esm-apps/jammy

not-affected

uses system libtiff
esm-apps/noble

not-affected

uses system libtiff
esm-apps/xenial

needed

Показывать по

РелизСтатусПримечание
bionic

not-affected

cosmic

ignored

end of life
devel

not-affected

disco

not-affected

eoan

not-affected

esm-apps/bionic

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

focal

not-affected

Показывать по

РелизСтатусПримечание
bionic

not-affected

uses system libtiff
cosmic

ignored

end of life
devel

DNE

disco

not-affected

uses system libtiff
eoan

not-affected

uses system libtiff
esm-apps/bionic

not-affected

uses system libtiff
esm-infra-legacy/trusty

not-affected

uses system libtiff
esm-infra/focal

DNE

esm-infra/xenial

not-affected

uses system libtiff
focal

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

needs-triage

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

needs-triage

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra-legacy/trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

needs-triage

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

Показывать по

РелизСтатусПримечание
bionic

released

4.0.9-5ubuntu0.2
cosmic

released

4.0.9-6ubuntu0.2
devel

not-affected

4.0.10-4
disco

not-affected

4.0.10-4
eoan

not-affected

4.0.10-4
esm-infra-legacy/trusty

not-affected

4.0.3-7ubuntu0.11
esm-infra/bionic

not-affected

4.0.9-5ubuntu0.2
esm-infra/focal

not-affected

4.0.10-4
esm-infra/xenial

not-affected

4.0.6-1ubuntu0.6
focal

not-affected

4.0.10-4

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

EPSS

Процентиль: 81%
0.01535
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

redhat
больше 6 лет назад

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

CVSS3: 6.5
nvd
больше 6 лет назад

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

CVSS3: 6.5
debian
больше 6 лет назад

An Invalid Address dereference was discovered in TIFFWriteDirectoryTag ...

CVSS3: 6.5
github
больше 3 лет назад

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.

fstec
больше 6 лет назад

Уязвимость функции TIFFWriteDirectoryTagTransferfunction программного обеспечения для просмотра, редактирования и конвертирования TIFF-файлов, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 81%
0.01535
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3