PT-2006-7532 · Kde+2 · Kdegraphics+3

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2006-3464

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libtiff versions prior to 3.8.2 kdegraphics versions 2.2.2 and 3.1.3 kdegraphics-devel versions 2.2.2 and 3.1.3
Description The issue involves multiple vulnerabilities in the libtiff and kdegraphics packages, which can lead to disruptions in the confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The libtiff library before version 3.8.2 is specifically vulnerable to context-dependent attacks that can pass numeric range checks, possibly execute code, and trigger assert errors via large offset values in a TIFF directory, leading to an integer overflow and other unspecified vectors involving "unchecked arithmetic operations".
Recommendations For libtiff versions prior to 3.8.2, update to version 3.8.2 or later. For kdegraphics versions 2.2.2 and 3.1.3, consider disabling the vulnerable components until a patch is available. For kdegraphics-devel versions 2.2.2 and 3.1.3, consider disabling the vulnerable components until a patch is available. As a temporary workaround, consider restricting access to the vulnerable modules to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00793
BDU:2015-04888
BDU:2015-04889
BDU:2015-04890
BDU:2015-04891
BDU:2015-04892
BDU:2015-04893
BDU:2015-04894
BDU:2015-06213
BDU:2015-06214
BDU:2015-06217
BDU:2015-06218
BDU:2015-09521
CVE-2006-3464
DSA-1137-1
RHSA-2006:0603
RHSA-2006:0648
RHSA-2006_0603

Affected Products

Red Hat
Kdegraphics
Kdegraphics-Devel
Libtiff