LWN.net Logo

libtiff: denial of service

Package(s):libtiff CVE #(s):CVE-2010-2443
Created:August 30, 2010 Updated:January 19, 2011
Description: From the MeeGo advisory:

The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function. CVSS v2 Base: 5.0 (MEDIUM) Access Vector: Network exploitable

Alerts:
MeeGo MeeGo-SA-10:27 2010-09-03
MeeGo MeeGo-SA-10:20 2010-08-03
Gentoo 201209-02 2012-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds