PT-2006-1050 · Tiff+2 · Tiff+2

Nitrous

·

Published

2006-05-30

·

Updated

2024-06-15

·

CVE-2006-2656

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: libtiff versions 3.8.2 and earlier tiff package versions prior to 3.8.2-r1
Description: A stack-based buffer overflow in the tiffsplit command could allow attackers to execute arbitrary code via a long filename. The issue might not be significant if there is no common scenario under which tiffsplit is called with attacker-controlled command line arguments. Multiple vulnerabilities in the tiff package may lead to disruption of confidentiality, integrity, and availability of protected information, and exploitation can be done remotely.
Recommendations: For libtiff versions 3.8.2 and earlier, consider updating to a version later than 3.8.2 to resolve the issue. For tiff package versions prior to 3.8.2-r1, update to version 3.8.2-r1 or later to fix the vulnerabilities. As a temporary workaround, consider restricting the use of the tiffsplit command until a patch is available. Avoid using long filenames when calling the tiffsplit command to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09506
CVE-2006-2656
DSA-1091-1
OPENSUSE-SU-2024:11461-1
RHSA-2006:0603
RHSA-2006_0603

Affected Products

Red Hat
Libtiff
Tiff