PT-2006-7531 · Libtiff+2 · Libtiff-32Bit+7

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2006-3463

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions kdegraphics versions 2.2.2 through 3.1.3 libtiff versions prior to 3.8.2 libtiff-devel versions prior to 3.8.2 libtiff-32bit versions prior to 3.8.2 libtiff-64bit versions prior to 3.8.2 libtiff-x86 versions prior to 3.8.2 libtiffxx0 versions prior to 3.8.2
Description The issue is related to multiple vulnerabilities in the libtiff package, which can lead to a denial of service. The EstimateStripByteCounts function in the TIFF library uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, allowing context-dependent attackers to cause a denial of service via a large td nstrips value, which triggers an infinite loop. The vulnerabilities can be exploited remotely.
Recommendations For kdegraphics versions 2.2.2 through 3.1.3, update to a version later than 3.1.3. For libtiff versions prior to 3.8.2, update to version 3.8.2 or later. For libtiff-devel versions prior to 3.8.2, update to version 3.8.2 or later. For libtiff-32bit versions prior to 3.8.2, update to version 3.8.2 or later. For libtiff-64bit versions prior to 3.8.2, update to version 3.8.2 or later. For libtiff-x86 versions prior to 3.8.2, update to version 3.8.2 or later. For libtiffxx0 versions prior to 3.8.2, update to version 3.8.2 or later.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00793
BDU:2015-04888
BDU:2015-04889
BDU:2015-04890
BDU:2015-04891
BDU:2015-04892
BDU:2015-04893
BDU:2015-04894
BDU:2015-06213
BDU:2015-06214
BDU:2015-06217
BDU:2015-06218
BDU:2015-09521
CVE-2006-3463
DSA-1137-1
RHSA-2006:0603
RHSA-2006:0648
RHSA-2006_0603

Affected Products

Red Hat
Kdegraphics
Libtiff
Libtiff-32Bit
Libtiff-64Bit
Libtiff-Devel
Libtiff-X86
Libtiffxx0