A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
{
"binaries": [
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "gdal-bin"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "libgdal-dev"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "libgdal-java"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "libgdal-perl"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "libgdal1-dev"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "libgdal1i"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "python-gdal"
},
{
"binary_version": "1.11.3+dfsg-3build2",
"binary_name": "python3-gdal"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "libqt5webengine-data"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "libqt5webengine5"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "libqt5webenginecore5"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "libqt5webenginewidgets5"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "qml-module-qtwebengine"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "qtwebengine5-dev"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "qtwebengine5-dev-tools"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "qtwebengine5-doc-html"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "qtwebengine5-examples"
},
{
"binary_version": "5.9.5+dfsg-0ubuntu2",
"binary_name": "qtwebengine5-private-dev"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "libqt5webengine-data"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "libqt5webengine5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "libqt5webenginecore5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "libqt5webenginewidgets5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "qml-module-qtwebengine"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "qtwebengine5-dev"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "qtwebengine5-dev-tools"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "qtwebengine5-doc-html"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "qtwebengine5-examples"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu1.1",
"binary_name": "qtwebengine5-private-dev"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "libqt5pdf5"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "libqt5pdfwidgets5"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "libqt5webengine-data"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "libqt5webengine5"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "libqt5webenginecore5"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "libqt5webenginewidgets5"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qml-module-qtquick-pdf"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qml-module-qtwebengine"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qt5-image-formats-plugin-pdf"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtpdf5-dev"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtpdf5-doc-html"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtpdf5-examples"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtwebengine5-dev"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtwebengine5-dev-tools"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtwebengine5-doc-html"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtwebengine5-examples"
},
{
"binary_version": "5.15.9+dfsg-1",
"binary_name": "qtwebengine5-private-dev"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.3.0-6ubuntu0.12",
"binary_name": "libtiff-dev"
},
{
"binary_version": "4.3.0-6ubuntu0.12",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.3.0-6ubuntu0.12",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.3.0-6ubuntu0.12",
"binary_name": "libtiff5"
},
{
"binary_version": "4.3.0-6ubuntu0.12",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.3.0-6ubuntu0.12",
"binary_name": "libtiffxx5"
}
],
"availability": "No subscription required",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "libqt5pdf5"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "libqt5pdfwidgets5"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "libqt5webengine-data"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "libqt5webengine5"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "libqt5webenginecore5"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "libqt5webenginewidgets5"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qml-module-qtquick-pdf"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qml-module-qtwebengine"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qt5-image-formats-plugin-pdf"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtpdf5-dev"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtpdf5-doc-html"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtpdf5-examples"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtwebengine5-dev"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtwebengine5-dev-tools"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtwebengine5-doc-html"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtwebengine5-examples"
},
{
"binary_version": "5.15.16+dfsg-3",
"binary_name": "qtwebengine5-private-dev"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.5.1+git230720-4ubuntu2.4",
"binary_name": "libtiff-dev"
},
{
"binary_version": "4.5.1+git230720-4ubuntu2.4",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.5.1+git230720-4ubuntu2.4",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.5.1+git230720-4ubuntu2.4",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.5.1+git230720-4ubuntu2.4",
"binary_name": "libtiff6"
},
{
"binary_version": "4.5.1+git230720-4ubuntu2.4",
"binary_name": "libtiffxx6"
}
],
"availability": "No subscription required",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "libqt5pdf5"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "libqt5pdfwidgets5"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "libqt5webengine-data"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "libqt5webengine5"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "libqt5webenginecore5"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "libqt5webenginewidgets5"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qml-module-qtquick-pdf"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qml-module-qtwebengine"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qt5-image-formats-plugin-pdf"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtpdf5-dev"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtpdf5-doc-html"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtpdf5-examples"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtwebengine5-dev"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtwebengine5-dev-tools"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtwebengine5-doc-html"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtwebengine5-examples"
},
{
"binary_version": "5.15.18+dfsg-2",
"binary_name": "qtwebengine5-private-dev"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.5.1+git230720-4ubuntu4.2",
"binary_name": "libtiff-dev"
},
{
"binary_version": "4.5.1+git230720-4ubuntu4.2",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.5.1+git230720-4ubuntu4.2",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.5.1+git230720-4ubuntu4.2",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.5.1+git230720-4ubuntu4.2",
"binary_name": "libtiff6"
},
{
"binary_version": "4.5.1+git230720-4ubuntu4.2",
"binary_name": "libtiffxx6"
}
],
"availability": "No subscription required",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "libqt5pdf5"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "libqt5pdfwidgets5"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "libqt5webengine-data"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "libqt5webengine5"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "libqt5webenginecore5"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "libqt5webenginewidgets5"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qml-module-qtquick-pdf"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qml-module-qtwebengine"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qt5-image-formats-plugin-pdf"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtpdf5-dev"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtpdf5-doc-html"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtpdf5-examples"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtwebengine5-dev"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtwebengine5-dev-tools"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtwebengine5-doc-html"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtwebengine5-examples"
},
{
"binary_version": "5.15.19+dfsg2-1",
"binary_name": "qtwebengine5-private-dev"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.7.0-3ubuntu3",
"binary_name": "libtiff-dev"
},
{
"binary_version": "4.7.0-3ubuntu3",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.7.0-3ubuntu3",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.7.0-3ubuntu3",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.7.0-3ubuntu3",
"binary_name": "libtiff6"
},
{
"binary_version": "4.7.0-3ubuntu3",
"binary_name": "libtiffxx6"
}
],
"availability": "No subscription required",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "gdal-bin"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "libgdal-dev"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "libgdal-java"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "libgdal-perl"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "libgdal1-dev"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "libgdal1h"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "python-gdal"
},
{
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1",
"binary_name": "python3-gdal"
}
],
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiff4-dev"
},
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiff5"
},
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiff5-alt-dev"
},
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.0.3-7ubuntu0.11+esm16",
"binary_name": "libtiffxx5"
}
],
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.0.6-1ubuntu0.8+esm19",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.0.6-1ubuntu0.8+esm19",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.0.6-1ubuntu0.8+esm19",
"binary_name": "libtiff5"
},
{
"binary_version": "4.0.6-1ubuntu0.8+esm19",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.0.6-1ubuntu0.8+esm19",
"binary_name": "libtiffxx5"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.0.9-5ubuntu0.10+esm9",
"binary_name": "libtiff-dev"
},
{
"binary_version": "4.0.9-5ubuntu0.10+esm9",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.0.9-5ubuntu0.10+esm9",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.0.9-5ubuntu0.10+esm9",
"binary_name": "libtiff5"
},
{
"binary_version": "4.0.9-5ubuntu0.10+esm9",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.0.9-5ubuntu0.10+esm9",
"binary_name": "libtiffxx5"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"priority_reason": "code execution with user permission"
}{
"binaries": [
{
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2",
"binary_name": "libtiff-dev"
},
{
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2",
"binary_name": "libtiff-opengl"
},
{
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2",
"binary_name": "libtiff-tools"
},
{
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2",
"binary_name": "libtiff5"
},
{
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2",
"binary_name": "libtiff5-dev"
},
{
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2",
"binary_name": "libtiffxx5"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"priority_reason": "code execution with user permission"
}