安全公告/【CVE-2022-1355】
基本信息
受影响操作系统:Asianux
危险等级:中危
影响源码包:libtiff
CVSS评分:6.1
发现日期:2022-11-23
修复版本:libtiff-4.0.9-23
漏洞描述
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
漏洞判定
执行命令yum info PackageName获取软件包版本号,版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复
修复方式
yum update PackageName