Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.2.2020.1235
Kategorie:Huawei EulerOS Local Security Checks
Titel:Huawei EulerOS: Security Advisory for libtiff (EulerOS-SA-2020-1235)
Zusammenfassung:The remote host is missing an update for the Huawei EulerOS 'libtiff' package(s) announced via the EulerOS-SA-2020-1235 advisory.
Beschreibung:Summary:
The remote host is missing an update for the Huawei EulerOS 'libtiff' package(s) announced via the EulerOS-SA-2020-1235 advisory.

Vulnerability Insight:
The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.(CVE-2016-5323)

The cvtClump function in the rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) by setting the '-v' option to -1.(CVE-2016-3624)

The rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero) by setting the (1) v or (2) h parameter to 0.(CVE-2016-3623)

LibTIFF 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode out-of-bounds write.(CVE-2018-18557)

An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.(CVE-2018-17101)

An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.(CVE-2018-17100)

In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.(CVE-2018-8905)

LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to 'WRITE of size 2048' and libtiff/tif_next.c:64:9.(CVE-2016-10272)

LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to 'READ of size 8' and libtiff/tif_read.c:523:22.(CVE-2016-10270)

LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to 'READ of size 512' and libtiff/tif_unix.c:340:2.(CVE-2016-10269)

tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based buffer under-read) or possibly have unspecified other impact via a crafted TIFF image, related to 'READ of size 78490' and libtiff/tif_unix.c:115:23.(CVE-2016-10268)

Heap-based buffer overflow in the readContigStripsIntoBuffer function in tif_unix.c in LibTIFF 4.0.7 allows remote attackers to have unspecified impact via a crafted image.(CVE-2016-10092)

The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'libtiff' package(s) on Huawei EulerOS Virtualization for ARM 64 3.0.2.0.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-3622
BugTraq ID: 85917
http://www.securityfocus.com/bid/85917
Debian Security Information: DSA-3762 (Google Search)
http://www.debian.org/security/2017/dsa-3762
https://security.gentoo.org/glsa/201701-16
http://www.openwall.com/lists/oss-security/2016/04/07/4
http://www.securitytracker.com/id/1035508
Common Vulnerability Exposure (CVE) ID: CVE-2016-3623
BugTraq ID: 85952
http://www.securityfocus.com/bid/85952
http://www.openwall.com/lists/oss-security/2016/04/08/3
SuSE Security Announcement: openSUSE-SU-2016:2275 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-09/msg00039.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-3624
BugTraq ID: 85956
http://www.securityfocus.com/bid/85956
http://bugzilla.maptools.org/show_bug.cgi?id=2568
http://www.openwall.com/lists/oss-security/2016/04/08/4
Common Vulnerability Exposure (CVE) ID: CVE-2016-5102
BugTraq ID: 96049
http://www.securityfocus.com/bid/96049
https://usn.ubuntu.com/3606-1/
Common Vulnerability Exposure (CVE) ID: CVE-2016-5318
BugTraq ID: 88604
http://www.securityfocus.com/bid/88604
http://www.openwall.com/lists/oss-security/2016/04/27/6
http://www.openwall.com/lists/oss-security/2016/06/07/1
Common Vulnerability Exposure (CVE) ID: CVE-2016-5321
BugTraq ID: 91209
http://www.securityfocus.com/bid/91209
SuSE Security Announcement: openSUSE-SU-2016:3035 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-5323
BugTraq ID: 91196
http://www.securityfocus.com/bid/91196
http://www.openwall.com/lists/oss-security/2016/06/15/6
Common Vulnerability Exposure (CVE) ID: CVE-2016-9273
BugTraq ID: 94271
http://www.securityfocus.com/bid/94271
http://www.openwall.com/lists/oss-security/2016/11/09/20
http://www.openwall.com/lists/oss-security/2016/11/11/6
Common Vulnerability Exposure (CVE) ID: CVE-2016-9538
BugTraq ID: 94484
http://www.securityfocus.com/bid/94484
BugTraq ID: 94753
http://www.securityfocus.com/bid/94753
Common Vulnerability Exposure (CVE) ID: CVE-2016-9539
BugTraq ID: 94754
http://www.securityfocus.com/bid/94754
Common Vulnerability Exposure (CVE) ID: CVE-2017-7592
BugTraq ID: 97510
http://www.securityfocus.com/bid/97510
Debian Security Information: DSA-3844 (Google Search)
http://www.debian.org/security/2017/dsa-3844
https://security.gentoo.org/glsa/201709-27
http://bugzilla.maptools.org/show_bug.cgi?id=2658
https://usn.ubuntu.com/3602-1/
Common Vulnerability Exposure (CVE) ID: CVE-2017-7593
BugTraq ID: 97502
http://www.securityfocus.com/bid/97502
http://bugzilla.maptools.org/show_bug.cgi?id=2651
Common Vulnerability Exposure (CVE) ID: CVE-2017-7594
BugTraq ID: 97503
http://www.securityfocus.com/bid/97503
http://bugzilla.maptools.org/show_bug.cgi?id=2659
Common Vulnerability Exposure (CVE) ID: CVE-2017-7595
BugTraq ID: 97501
http://www.securityfocus.com/bid/97501
https://blogs.gentoo.org/ago/2017/04/01/libtiff-divide-by-zero-in-jpegsetupencode-tiff_jpeg-c
Common Vulnerability Exposure (CVE) ID: CVE-2017-7596
BugTraq ID: 97506
http://www.securityfocus.com/bid/97506
https://blogs.gentoo.org/ago/2017/04/01/libtiff-multiple-ubsan-crashes
Common Vulnerability Exposure (CVE) ID: CVE-2017-7597
BugTraq ID: 97504
http://www.securityfocus.com/bid/97504
Common Vulnerability Exposure (CVE) ID: CVE-2017-7598
BugTraq ID: 97499
http://www.securityfocus.com/bid/97499
Common Vulnerability Exposure (CVE) ID: CVE-2017-7599
BugTraq ID: 97505
http://www.securityfocus.com/bid/97505
BugTraq ID: 97508
http://www.securityfocus.com/bid/97508
Common Vulnerability Exposure (CVE) ID: CVE-2017-7600
Common Vulnerability Exposure (CVE) ID: CVE-2017-7601
BugTraq ID: 97511
http://www.securityfocus.com/bid/97511
Common Vulnerability Exposure (CVE) ID: CVE-2017-7602
BugTraq ID: 97500
http://www.securityfocus.com/bid/97500
Common Vulnerability Exposure (CVE) ID: CVE-2017-9117
BugTraq ID: 98581
http://www.securityfocus.com/bid/98581
http://bugzilla.maptools.org/show_bug.cgi?id=2690
Common Vulnerability Exposure (CVE) ID: CVE-2017-9147
BugTraq ID: 98594
http://www.securityfocus.com/bid/98594
Debian Security Information: DSA-3903 (Google Search)
http://www.debian.org/security/2017/dsa-3903
https://www.exploit-db.com/exploits/42301/
http://bugzilla.maptools.org/show_bug.cgi?id=2693
Common Vulnerability Exposure (CVE) ID: CVE-2017-9403
Common Vulnerability Exposure (CVE) ID: CVE-2017-9936
BugTraq ID: 99300
http://www.securityfocus.com/bid/99300
https://www.exploit-db.com/exploits/42300/
http://bugzilla.maptools.org/show_bug.cgi?id=2706
Common Vulnerability Exposure (CVE) ID: CVE-2018-7456
Debian Security Information: DSA-4349 (Google Search)
https://www.debian.org/security/2018/dsa-4349
http://bugzilla.maptools.org/show_bug.cgi?id=2778
https://github.com/xiaoqx/pocs/tree/master/libtiff
https://lists.debian.org/debian-lts-announce/2018/04/msg00010.html
https://lists.debian.org/debian-lts-announce/2018/04/msg00011.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00002.html
RedHat Security Advisories: RHSA-2019:2051
https://access.redhat.com/errata/RHSA-2019:2051
RedHat Security Advisories: RHSA-2019:2053
https://access.redhat.com/errata/RHSA-2019:2053
https://usn.ubuntu.com/3864-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-8905
http://bugzilla.maptools.org/show_bug.cgi?id=2780
https://github.com/halfbitteam/POCs/tree/master/libtiff-4.08_tiff2ps_heap_overflow
https://lists.debian.org/debian-lts-announce/2018/05/msg00008.html
https://lists.debian.org/debian-lts-announce/2018/05/msg00009.html
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.