PT-2017-1216 · Libtiff+2 · Libtiff+2
Pxo炳林
·
Publicado
2017-01-20
·
Atualizado
2019-04-10
·
CVE-2016-5319
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libtiff versions 4.0.6 and earlier
Description
The issue is caused by a heap-based buffer overflow in the tif packbits.c function of the LibTIFF library. This can be exploited by a remote attacker using a specially crafted BMP file, potentially leading to a crash of the application.
Recommendations
For libtiff versions 4.0.6 and earlier, consider restricting the use of the tif packbits.c function until a patch is available.
As a temporary workaround, avoid using the LibTIFF library to process untrusted BMP files until the issue is resolved.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Libtiff