Lucene search

K
ubuntuUbuntuUSN-54-1
HistoryJan 07, 2005 - 12:00 a.m.

TIFF library tool vulnerability

2005-01-0700:00:00
ubuntu.com
42

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.082 Low

EPSS

Percentile

94.4%

Releases

  • Ubuntu 4.10

Details

Dmitry V. Levin discovered a buffer overflow in the “tiffdump”
utility. If an attacker tricked a user into processing a malicious
TIFF image with tiffdump, they could cause a buffer overflow which at
least causes the program to crash. However, it is not entirely clear
whether this can be exploited to execute arbitrary code with the
privileges of the user opening the image.

OSVersionArchitecturePackageVersionFilename
Ubuntu4.10noarchlibtiff-tools< *UNKNOWN

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.082 Low

EPSS

Percentile

94.4%