Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2019.0366
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2019-0366)
Zusammenfassung:The remote host is missing an update for the 'libtiff' package(s) announced via the MGASA-2019-0366 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'libtiff' package(s) announced via the MGASA-2019-0366 advisory.

Vulnerability Insight:
The updated packages fix a security vulnerability:

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1
and other products, has an integer overflow that potentially causes a
heap-based buffer overflow via a crafted RGBA image, related to a
'Negative-size-param' condition (CVE-2019-17546).

Affected Software/OS:
'libtiff' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-17546
Bugtraq: 20200121 [SECURITY] [DSA 4608-1] tiff security update (Google Search)
https://seclists.org/bugtraq/2020/Jan/32
Debian Security Information: DSA-4608 (Google Search)
https://www.debian.org/security/2020/dsa-4608
Debian Security Information: DSA-4670 (Google Search)
https://www.debian.org/security/2020/dsa-4670
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LM5ZW7E3IEW7LT2BPJP7D3RN6OUOE3MX/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M3S4WNIMZ7XSLY2LD5FPRPZMGNUBVKOG/
https://security.gentoo.org/glsa/202003-25
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443
https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf
https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145
https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html
https://lists.debian.org/debian-lts-announce/2020/03/msg00020.html
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.