PT-2010-1057 · Tiff+3 · Tiff+3

Tom Lane

·

Published

2010-07-01

·

Updated

2014-02-28

·

CVE-2010-2596

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF versions 3.9.0 through 3.9.4 tiff versions prior to 4.0.2-r1
Description The issue concerns multiple vulnerabilities in the LibTIFF package, which can lead to disruptions in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The OJPEGPostDecode function in tif ojpeg.c is specifically mentioned as allowing remote attackers to cause a denial of service via a crafted TIFF image, related to "downsampled OJPEG input."
Recommendations For LibTIFF versions 3.9.0 through 3.9.4, update to a version later than 3.9.4 to resolve the issue. For tiff versions prior to 4.0.2-r1, update to version 4.0.2-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to TIFF images from untrusted sources until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06338
BDU:2015-06340
BDU:2015-06344
BDU:2015-06345
BDU:2015-08609
BDU:2015-08610
BDU:2015-08611
BDU:2015-08612
BDU:2015-09646
CESA-2014_0222
CVE-2010-2596
DLA-610-1
RHSA-2014:0222
RHSA-2014_0222

Affected Products

Centos
Libtiff
Red Hat
Tiff