CVE-2018-7456
tiff3 - security update
6.5
MEDIUM
CVSS 3.1
EPSS 3.0%
描述
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)
如何修補 CVE-2018-7456
要修補 CVE-2018-7456,請將受影響套件升級到下列已修補版本。
- —升級至 4.0.9-r4 或更新版本
- —升級至 4.0.9-5 或更新版本
- —升級至 4.0.2-6+deb7u19 或更新版本
- —升級至 3.9.6-11+deb7u10 或更新版本
CVE-2018-7456 正在被利用嗎?
低 — EPSS 為 3.0%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 4.0.9-r4
- from 0, < 4.0.9-5
- from 0, < 4.0.2-6+deb7u19
- from 0, < 3.9.6-11+deb7u10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |