Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-41175

Опубликовано: 05 окт. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

4.5.1+git230720-1ubuntu1
esm-infra-legacy/trusty

not-affected

4.0.3-7ubuntu0.11+esm9
esm-infra/bionic

not-affected

4.0.9-5ubuntu0.10+esm2
esm-infra/focal

not-affected

4.1.0+git191117-2ubuntu0.20.04.9
esm-infra/xenial

not-affected

4.0.6-1ubuntu0.8+esm12
focal

not-affected

4.1.0+git191117-2ubuntu0.20.04.9
jammy

not-affected

4.3.0-6ubuntu0.5
lunar

not-affected

4.5.0-5ubuntu1.1
trusty

ignored

end of standard support

Показывать по

Ссылки на источники

EPSS

Процентиль: 49%
0.00261
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
почти 2 года назад

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVSS3: 6.5
nvd
больше 1 года назад

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVSS3: 6.5
debian
больше 1 года назад

A vulnerability was found in libtiff due to multiple potential integer ...

CVSS3: 6.5
github
больше 1 года назад

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость компонента raw2tiff.c библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 49%
0.00261
Низкий

6.5 Medium

CVSS3