PT-2006-3100 · Libtiff+1 · Libtiff+1

Josh Bressers

·

Published

2006-05-01

·

Updated

2018-10-03

·

CVE-2006-2120

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libtiff versions prior to 3.8.1
Description The issue allows remote attackers to cause a denial of service (crash) via a crafted TIFF image. This is triggered by Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, resulting in an out-of-bounds read.
Recommendations For versions prior to 3.8.1, update to version 3.8.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TIFFToRGB function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2120
DSA-1078-1
RHSA-2006:0425
RHSA-2006_0425

Affected Products

Red Hat
Libtiff