Описание
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | uses system tiff |
| esm-apps-legacy/xenial | released | 1.11.3+dfsg-3ubuntu0.1~esm1 |
| esm-apps/bionic | not-affected | uses system tiff |
| esm-apps/focal | not-affected | uses system tiff |
| esm-apps/jammy | not-affected | uses system tiff |
| esm-apps/noble | not-affected | uses system tiff |
| esm-apps/resolute | not-affected | uses system tiff |
| esm-apps/xenial | ignored | end of ESM support, was needed |
| esm-infra-legacy/trusty | released | 1.10.1+dfsg-5ubuntu1+esm2 |
| jammy | not-affected | uses system tiff |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | dropped embedded libtiff |
| esm-apps/bionic | not-affected | code not present |
| esm-apps/focal | not-affected | code not present |
| esm-apps/jammy | not-affected | code not present |
| esm-apps/noble | not-affected | dropped embedded libtiff |
| esm-apps/resolute | not-affected | dropped embedded libtiff |
| jammy | not-affected | code not present |
| noble | not-affected | dropped embedded libtiff |
| plucky | not-affected | dropped embedded libtiff |
| questing | not-affected | dropped embedded libtiff |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-apps/bionic | released | 5.9.5+dfsg-0ubuntu2+esm1 |
| esm-apps/focal | released | 5.12.8+dfsg-0ubuntu1.1+esm1 |
| esm-apps/jammy | released | 5.15.9+dfsg-1ubuntu0.1~esm1 |
| esm-apps/noble | released | 5.15.16+dfsg-3ubuntu0.1~esm1 |
| esm-apps/resolute | released | 5.15.19+dfsg2-4ubuntu0.1~esm1 |
| jammy | needed | |
| noble | needed | |
| plucky | ignored | end of life, was needed |
| questing | ignored | end of life, was needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | uses system tiff |
| esm-apps-legacy/xenial | not-affected | code not present |
| esm-apps/bionic | released | 5.0.2-1ubuntu0.1~esm1 |
| esm-apps/focal | released | 5.0.3-1ubuntu0.20.04.1~esm1 |
| esm-apps/jammy | released | 5.0.3-1ubuntu0.22.04.1~esm1 |
| esm-apps/noble | released | 5.1.3+dfsg-1ubuntu0.1~esm1 |
| esm-apps/resolute | not-affected | uses system tiff |
| esm-apps/xenial | not-affected | code not present |
| jammy | needed | |
| noble | needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 4.7.0-3ubuntu3 |
| esm-infra-legacy/trusty | released | 4.0.3-7ubuntu0.11+esm16 |
| esm-infra-legacy/xenial | released | 4.0.6-1ubuntu0.8+esm19 |
| esm-infra/bionic | released | 4.0.9-5ubuntu0.10+esm9 |
| esm-infra/focal | released | 4.1.0+git191117-2ubuntu0.20.04.14+esm2 |
| esm-infra/xenial | released | 4.0.6-1ubuntu0.8+esm19 |
| jammy | released | 4.3.0-6ubuntu0.12 |
| noble | released | 4.5.1+git230720-4ubuntu2.4 |
| plucky | released | 4.5.1+git230720-4ubuntu4.2 |
| questing | released | 4.7.0-3ubuntu3 |
Показывать по
Ссылки на источники
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
A flaw was found in Libtiff. This vulnerability is a "write-what-where ...
EPSS
8.8 High
CVSS3