Lucene search

K
freebsdFreeBSD68222076-010B-11DA-BC08-0001020EED82
HistoryMay 10, 2005 - 12:00 a.m.

tiff -- buffer overflow vulnerability

2005-05-1000:00:00
vuxml.freebsd.org
19

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.335 Low

EPSS

Percentile

97.1%

A Gentoo Linux Security Advisory reports:

Tavis Ormandy of the Gentoo Linux Security Audit Team
discovered a stack based buffer overflow in the libTIFF
library when reading a TIFF image with a malformed
BitsPerSample tag.
Successful exploitation would require the victim to open
a specially crafted TIFF image, resulting in the execution
of arbitrary code.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.335 Low

EPSS

Percentile

97.1%