PT-2010-1131 · Libtiff+1 · Libtiff+1

Sauli Pahlman

·

Publicado

2010-07-01

·

Atualizado

2013-05-15

·

CVE-2010-2597

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF versions prior to 4.0.2
Description The issue is related to multiple vulnerabilities in the tiff package, which can lead to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. Specifically, the TIFFVStripSize function in tif strip.c makes incorrect calls to the TIFFGetField function, allowing remote attackers to cause a denial of service via a crafted TIFF image, possibly related to "downsampled OJPEG input" and a compiler optimization that triggers a divide-by-zero error.
Recommendations For versions prior to 4.0.2, update to version 4.0.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TIFFVStripSize function in tif strip.c until a patch is available. Avoid using the TIFFGetField function with untrusted input in the affected API endpoints until the issue is resolved.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09646
CVE-2010-2597
DSA-2552-1
RHSA-2010:0519
RHSA-2010_0519

Produtos afetados

Libtiff
Red Hat