Open mend-bolt-for-github[bot] opened 11 months ago
Library home page: https://github.com/TinkerEdgeR-Android/external_pdfium.git
Found in base branch: master
/third_party/libtiff/tif_luv.c
There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.
Publish Date: 2023-08-22
URL: CVE-2020-18768
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High
Type: Upgrade version
Origin: http://bugzilla.maptools.org/show_bug.cgi?id=2848
Release Date: 2023-08-22
Fix Resolution: v4.1.0
Step up your Open Source Security Game with Mend here
CVE-2020-18768 - Medium Severity Vulnerability
Vulnerable Library - external_pdfiumtinker_edge_r-android9-1.0.2
Library home page: https://github.com/TinkerEdgeR-Android/external_pdfium.git
Found in base branch: master
Vulnerable Source Files (1)
/third_party/libtiff/tif_luv.c
Vulnerability Details
There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.
Publish Date: 2023-08-22
URL: CVE-2020-18768
CVSS 3 Score Details (5.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: http://bugzilla.maptools.org/show_bug.cgi?id=2848
Release Date: 2023-08-22
Fix Resolution: v4.1.0
Step up your Open Source Security Game with Mend here