PT-2017-1216 · Libtiff+2 · Libtiff+2

Pxo炳林

·

Publicado

2017-01-20

·

Atualizado

2019-04-10

·

CVE-2016-5319

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtiff versions 4.0.6 and earlier
Description The issue is caused by a heap-based buffer overflow in the tif packbits.c function of the LibTIFF library. This can be exploited by a remote attacker using a specially crafted BMP file, potentially leading to a crash of the application.
Recommendations For libtiff versions 4.0.6 and earlier, consider restricting the use of the tif packbits.c function until a patch is available. As a temporary workaround, avoid using the LibTIFF library to process untrusted BMP files until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1628
BDU:2017-00329
CVE-2016-5319
DLA-693-1
MGASA-2018-0409
OPENSUSE-SU-2018_2880-1
SUSE-SU-2018:2676-1
SUSE-SU-2018:2836-1
SUSE-SU-2018:3879-1
SUSE-SU-2018_2836-1

Produtos afetados

Alt Linux
Suse
Libtiff