|
|
| |
|
| |
libtiff: denial of service
| Package(s): | libtiff |
CVE #(s): | CVE-2010-2443
|
| Created: | August 30, 2010 |
Updated: | January 19, 2011 |
| Description: |
From the MeeGo advisory:
The OJPEGReadBufferFill function in tif_ojpeg.c in
LibTIFF before 3.9.3 allows remote attackers to cause a denial of
service (NULL pointer dereference and application crash) via an OJPEG
image with undefined strip offsets, related to the TIFFVGetField
function.
CVSS v2 Base: 5.0 (MEDIUM)
Access Vector: Network exploitable
|
| Alerts: |
|
( Log in to post comments)
|
|
|