PT-2006-3100 · Libtiff+1 · Libtiff+1
Josh Bressers
·
Published
2006-05-01
·
Updated
2018-10-03
·
CVE-2006-2120
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libtiff versions prior to 3.8.1
Description
The issue allows remote attackers to cause a denial of service (crash) via a crafted TIFF image. This is triggered by Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, resulting in an out-of-bounds read.
Recommendations
For versions prior to 3.8.1, update to version 3.8.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TIFFToRGB function until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Libtiff