PT-2010-5608 · Sam Leffler+1 · Libtiff-Tools+9

Publicado

1970-01-01

·

Atualizado

2013-05-15

·

CVE-2010-1411

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libtiff-devel-3.5.7 tiff versions prior to 4.0.2-r1 libtiff4 (affected versions not specified) libtiff4-dev (affected versions not specified) libtiff-opengl (affected versions not specified) libtiff-doc (affected versions not specified) libtiffxx0c2 (affected versions not specified) libtiff-tools (affected versions not specified)
Description The issue involves multiple vulnerabilities in the libtiff package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The Fax3SetupState function in tif fax3.c in the FAX3 decoder in LibTIFF is affected by multiple integer overflows, allowing remote attackers to execute arbitrary code or cause a denial of service via a crafted TIFF file.
Recommendations For libtiff-devel-3.5.7, update to a version that contains a fix for this issue. For tiff versions prior to 4.0.2-r1, update to version 4.0.2-r1 or later. For libtiff4, libtiff4-dev, libtiff-opengl, libtiff-doc, libtiffxx0c2, and libtiff-tools, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00789
BDU:2015-00790
BDU:2015-00791
BDU:2015-00792
BDU:2015-02008
BDU:2015-02009
BDU:2015-06342
BDU:2015-08600
BDU:2015-09646
CVE-2010-1411
DSA-2084-1
RHSA-2010:0519
RHSA-2010:0520
RHSA-2010_0519

Produtos afetados

Red Hat
Libtiff
Libtiff-Devel
Libtiff-Doc
Libtiff-Opengl
Libtiff-Tools
Libtiff4
Libtiff4-Dev
Libtiffxx0C2
Tiff