PT-2009-5608 · None · Camlimages

Published

2009-10-20

·

Updated

2009-10-21

·

CVE-2009-3296

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CamlImages version 2.2
Description The issue is related to multiple integer overflows in the tiffread.c file, which can be triggered by TIFF images with large width and height values. This could potentially lead to heap-based buffer overflows, allowing remote attackers to execute arbitrary code.
Recommendations For CamlImages version 2.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3296
DSA-1912-1
DSA-1912-2

Affected Products

Camlimages