LWN.net Logo

tiff: arbitrary code execution

Package(s):tiff CVE #(s):
Created:June 15, 2010 Updated:June 16, 2010
Description: From the Pardus advisory:

Multiple integer overflows in the handling of TIFF files may result in a heap buffer overflow. Opening a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution. These issues are addressed through improved bounds checking. Credit to Kevin Finisterre of digitalmunition.com for reporting this issue.

Alerts:
Pardus 2010-81 2010-06-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds