A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "gdal-bin",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal-dev",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal-java",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal-perl",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal1-dev",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal1i",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "python-gdal",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "python3-gdal",
"binary_version": "1.11.3+dfsg-3build2"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "libqt5webengine-data",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "libqt5webengine5",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "libqt5webenginecore5",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "libqt5webenginewidgets5",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "qml-module-qtwebengine",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "qtwebengine5-dev",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "qtwebengine5-dev-tools",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "qtwebengine5-doc-html",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "qtwebengine5-examples",
"binary_version": "5.9.5+dfsg-0ubuntu2"
},
{
"binary_name": "qtwebengine5-private-dev",
"binary_version": "5.9.5+dfsg-0ubuntu2"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "libqt5webengine-data",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "libqt5webengine5",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "libqt5webenginecore5",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "libqt5webenginewidgets5",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "qml-module-qtwebengine",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "qtwebengine5-dev",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "qtwebengine5-dev-tools",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "qtwebengine5-doc-html",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "qtwebengine5-examples",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
},
{
"binary_name": "qtwebengine5-private-dev",
"binary_version": "5.12.8+dfsg-0ubuntu1.1"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "libqt5pdf5",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "libqt5pdfwidgets5",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "libqt5webengine-data",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "libqt5webengine5",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "libqt5webenginecore5",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "libqt5webenginewidgets5",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qml-module-qtquick-pdf",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qml-module-qtwebengine",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qt5-image-formats-plugin-pdf",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtpdf5-dev",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtpdf5-doc-html",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtpdf5-examples",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtwebengine5-dev",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtwebengine5-dev-tools",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtwebengine5-doc-html",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtwebengine5-examples",
"binary_version": "5.15.9+dfsg-1"
},
{
"binary_name": "qtwebengine5-private-dev",
"binary_version": "5.15.9+dfsg-1"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtiff-dev",
"binary_version": "4.3.0-6ubuntu0.12"
},
{
"binary_name": "libtiff-opengl",
"binary_version": "4.3.0-6ubuntu0.12"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.3.0-6ubuntu0.12"
},
{
"binary_name": "libtiff5",
"binary_version": "4.3.0-6ubuntu0.12"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.3.0-6ubuntu0.12"
},
{
"binary_name": "libtiffxx5",
"binary_version": "4.3.0-6ubuntu0.12"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "libqt5pdf5",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "libqt5pdfwidgets5",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "libqt5webengine-data",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "libqt5webengine5",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "libqt5webenginecore5",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "libqt5webenginewidgets5",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qml-module-qtquick-pdf",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qml-module-qtwebengine",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qt5-image-formats-plugin-pdf",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtpdf5-dev",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtpdf5-doc-html",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtpdf5-examples",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtwebengine5-dev",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtwebengine5-dev-tools",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtwebengine5-doc-html",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtwebengine5-examples",
"binary_version": "5.15.16+dfsg-3"
},
{
"binary_name": "qtwebengine5-private-dev",
"binary_version": "5.15.16+dfsg-3"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtiff-dev",
"binary_version": "4.5.1+git230720-4ubuntu2.4"
},
{
"binary_name": "libtiff-opengl",
"binary_version": "4.5.1+git230720-4ubuntu2.4"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.5.1+git230720-4ubuntu2.4"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.5.1+git230720-4ubuntu2.4"
},
{
"binary_name": "libtiff6",
"binary_version": "4.5.1+git230720-4ubuntu2.4"
},
{
"binary_name": "libtiffxx6",
"binary_version": "4.5.1+git230720-4ubuntu2.4"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "libqt5pdf5",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "libqt5pdfwidgets5",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "libqt5webengine-data",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "libqt5webengine5",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "libqt5webenginecore5",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "libqt5webenginewidgets5",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qml-module-qtquick-pdf",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qml-module-qtwebengine",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qt5-image-formats-plugin-pdf",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtpdf5-dev",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtpdf5-doc-html",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtpdf5-examples",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtwebengine5-dev",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtwebengine5-dev-tools",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtwebengine5-doc-html",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtwebengine5-examples",
"binary_version": "5.15.18+dfsg-2"
},
{
"binary_name": "qtwebengine5-private-dev",
"binary_version": "5.15.18+dfsg-2"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtiff-dev",
"binary_version": "4.5.1+git230720-4ubuntu4.2"
},
{
"binary_name": "libtiff-opengl",
"binary_version": "4.5.1+git230720-4ubuntu4.2"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.5.1+git230720-4ubuntu4.2"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.5.1+git230720-4ubuntu4.2"
},
{
"binary_name": "libtiff6",
"binary_version": "4.5.1+git230720-4ubuntu4.2"
},
{
"binary_name": "libtiffxx6",
"binary_version": "4.5.1+git230720-4ubuntu4.2"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "libqt5pdf5",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "libqt5pdfwidgets5",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "libqt5webengine-data",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "libqt5webengine5",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "libqt5webenginecore5",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "libqt5webenginewidgets5",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qml-module-qtquick-pdf",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qml-module-qtwebengine",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qt5-image-formats-plugin-pdf",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtpdf5-dev",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtpdf5-doc-html",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtpdf5-examples",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtwebengine5-dev",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtwebengine5-dev-tools",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtwebengine5-doc-html",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtwebengine5-examples",
"binary_version": "5.15.19+dfsg2-1"
},
{
"binary_name": "qtwebengine5-private-dev",
"binary_version": "5.15.19+dfsg2-1"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtiff-dev",
"binary_version": "4.7.0-3ubuntu3"
},
{
"binary_name": "libtiff-opengl",
"binary_version": "4.7.0-3ubuntu3"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.7.0-3ubuntu3"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.7.0-3ubuntu3"
},
{
"binary_name": "libtiff6",
"binary_version": "4.7.0-3ubuntu3"
},
{
"binary_name": "libtiffxx6",
"binary_version": "4.7.0-3ubuntu3"
}
]
}{
"priority_reason": "code execution with user permission",
"binaries": [
{
"binary_name": "gdal-bin",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal-dev",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal-java",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal-perl",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal1-dev",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal1h",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "python-gdal",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "python3-gdal",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libtiff-opengl",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
},
{
"binary_name": "libtiff4-dev",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
},
{
"binary_name": "libtiff5",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
},
{
"binary_name": "libtiff5-alt-dev",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
},
{
"binary_name": "libtiffxx5",
"binary_version": "4.0.3-7ubuntu0.11+esm16"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libtiff-opengl",
"binary_version": "4.0.6-1ubuntu0.8+esm19"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.0.6-1ubuntu0.8+esm19"
},
{
"binary_name": "libtiff5",
"binary_version": "4.0.6-1ubuntu0.8+esm19"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.0.6-1ubuntu0.8+esm19"
},
{
"binary_name": "libtiffxx5",
"binary_version": "4.0.6-1ubuntu0.8+esm19"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libtiff-dev",
"binary_version": "4.0.9-5ubuntu0.10+esm9"
},
{
"binary_name": "libtiff-opengl",
"binary_version": "4.0.9-5ubuntu0.10+esm9"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.0.9-5ubuntu0.10+esm9"
},
{
"binary_name": "libtiff5",
"binary_version": "4.0.9-5ubuntu0.10+esm9"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.0.9-5ubuntu0.10+esm9"
},
{
"binary_name": "libtiffxx5",
"binary_version": "4.0.9-5ubuntu0.10+esm9"
}
]
}{
"priority_reason": "code execution with user permission",
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libtiff-dev",
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
},
{
"binary_name": "libtiff-opengl",
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
},
{
"binary_name": "libtiff-tools",
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
},
{
"binary_name": "libtiff5",
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
},
{
"binary_name": "libtiff5-dev",
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
},
{
"binary_name": "libtiffxx5",
"binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
}
]
}