LibTIFF TiffFetchShortPair远程缓冲区溢出漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Libtiff是一种TIFF规范的标准ANSI C实现库。 Libtiff包含的tif_dirread.c存在多个堆栈溢出,远程攻击者可以利用漏洞以应用进程权限执行任意命令。 TIFFFetchShortPair()用于从输入文件中读取两个无符号短整数,其通过CheckDirCount()进行边界检查,但对tdir_count数据缺少正确检查,可导致拒绝服务攻击,也可能以应用进程权限执行任意命令。 S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Enterprise Server 10 + Linux kernel 2.6.5 S.u.S.E. Linux Enterprise SDK 10 S.u.S.E. Linux Desktop 1.0 rPath rPath Linux 1 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Linux Mandrake 2006.0...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息