Описание
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | uses system tiff |
| esm-apps/bionic | not-affected | uses system tiff |
| esm-apps/focal | not-affected | uses system tiff |
| esm-apps/jammy | not-affected | uses system tiff |
| esm-apps/noble | not-affected | uses system tiff |
| esm-apps/xenial | needs-triage | |
| esm-infra-legacy/trusty | needs-triage | |
| jammy | not-affected | uses system tiff |
| noble | not-affected | uses system tiff |
| plucky | not-affected | uses system tiff |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | dropped embedded libtiff |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | not-affected | dropped embedded libtiff |
| jammy | needs-triage | |
| noble | not-affected | dropped embedded libtiff |
| plucky | not-affected | dropped embedded libtiff |
| questing | not-affected | dropped embedded libtiff |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| plucky | needs-triage | |
| questing | needs-triage | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/xenial | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| plucky | needs-triage | |
| questing | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4.7.0-3ubuntu1 |
| esm-infra-legacy/trusty | released | 4.0.3-7ubuntu0.11+esm15 |
| esm-infra/bionic | released | 4.0.9-5ubuntu0.10+esm8 |
| esm-infra/focal | released | 4.1.0+git191117-2ubuntu0.20.04.14+esm1 |
| esm-infra/xenial | released | 4.0.6-1ubuntu0.8+esm18 |
| jammy | released | 4.3.0-6ubuntu0.11 |
| noble | released | 4.5.1+git230720-4ubuntu2.3 |
| plucky | released | 4.5.1+git230720-4ubuntu4.1 |
| questing | not-affected | 4.7.0-3ubuntu1 |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.
LibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by thi ...
EPSS
4.3 Medium
CVSS2
5.3 Medium
CVSS3