Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
dcraw 缓冲区错误漏洞
Vulnerability Description
dcraw是美国软件开发者David J. Coffin所研发的一套开源的用于把相机拍的RAW片转换成PPM或者TIFF格式的图片的工具。 dcraw 9.28及之前版本中的parse_tiff_ifd存在基于堆的缓冲区越界读取漏洞。攻击者可借助恶意文件利用该漏洞造成应用程序崩溃或泄露私有信息。
CVSS Information
N/A
Vulnerability Type
N/A