Tiff · Tiff · CVE-2009-2285
**Name of the Vulnerable Software and Affected Versions**
libtiff versions prior to 3.8.2
tiff package versions prior to 3.8.2-r8
**Description**
The issue is related to a buffer underflow in the LZWDecodeCompat function, allowing context-dependent attackers to cause a denial of service via a crafted TIFF image. Multiple vulnerabilities in the tiff package can lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
**Recommendations**
For libtiff versions prior to 3.8.2, update to version 3.8.2 or later to resolve the issue.
For tiff package versions prior to 3.8.2-r8, update to version 3.8.2-r8 or later to resolve the issue.