PT-2006-1050 · Tiff+2 · Tiff+2
Nitrous
·
Published
2006-05-30
·
Updated
2024-06-15
·
CVE-2006-2656
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
libtiff versions 3.8.2 and earlier
tiff package versions prior to 3.8.2-r1
Description:
A stack-based buffer overflow in the tiffsplit command could allow attackers to execute arbitrary code via a long filename. The issue might not be significant if there is no common scenario under which tiffsplit is called with attacker-controlled command line arguments. Multiple vulnerabilities in the tiff package may lead to disruption of confidentiality, integrity, and availability of protected information, and exploitation can be done remotely.
Recommendations:
For libtiff versions 3.8.2 and earlier, consider updating to a version later than 3.8.2 to resolve the issue.
For tiff package versions prior to 3.8.2-r1, update to version 3.8.2-r1 or later to fix the vulnerabilities.
As a temporary workaround, consider restricting the use of the tiffsplit command until a patch is available.
Avoid using long filenames when calling the tiffsplit command to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Libtiff
Tiff