PT-2010-1129 · Tiff+2 · Tiff+2

Published

2010-07-06

·

Updated

2023-02-13

·

CVE-2010-2483

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF version 3.9.0 tiff versions prior to 4.0.2-r1
Description The issue allows remote attackers to cause a denial of service, potentially leading to an out-of-bounds read and application crash, via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values. Multiple vulnerabilities in the tiff package may lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For LibTIFF version 3.9.0, update to a version newer than 3.9.0 to resolve the issue. For tiff versions prior to 4.0.2-r1, update to version 4.0.2-r1 or newer to mitigate the risk. As a temporary workaround, consider restricting the use of the TIFFRGBAImageGet function until a patch is available.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-09646
CVE-2010-2483
RHSA-2010:0519
RHSA-2010_0519

Affected Products

Libtiff
Red Hat
Tiff