VDB
BDU%3A2020-00196
BDU%3A2020-00196
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Уязвимость функции LZWDecode библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Red Hat Inc., Silicon Graphics Corp., Сообщество свободного программного обеспечения | Ubuntu, Red Hat Enterprise Linux, LibTIFF, Debian GNU/Linux |
Timeline
- Jan 22, 2020 CVE Published
- Mar 18, 2026 Distribution Patch
References
- http://bugzilla.maptools.org/show_bug.cgi?id=2819 url
- http://www.securityfocus.com/bid/105762 url
- https://access.redhat.com/errata/RHSA-2019:2053 url
- https://lists.debian.org/debian-lts-announce/2019/11/msg00027.html url
- https://usn.ubuntu.com/3864-1/ url
- https://gitlab.com/libtiff/libtiff/commit/99b10edde9a0fc28cc0e7b7757aa18ac4c8c225f advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1644448 advisory