PT-2010-5608 · Sam Leffler+1 · Libtiff-Tools+9
Published
1970-01-01
·
Updated
2013-05-15
·
CVE-2010-1411
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libtiff-devel-3.5.7
tiff versions prior to 4.0.2-r1
libtiff4 (affected versions not specified)
libtiff4-dev (affected versions not specified)
libtiff-opengl (affected versions not specified)
libtiff-doc (affected versions not specified)
libtiffxx0c2 (affected versions not specified)
libtiff-tools (affected versions not specified)
Description
The issue involves multiple vulnerabilities in the libtiff package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The Fax3SetupState function in tif fax3.c in the FAX3 decoder in LibTIFF is affected by multiple integer overflows, allowing remote attackers to execute arbitrary code or cause a denial of service via a crafted TIFF file.
Recommendations
For libtiff-devel-3.5.7, update to a version that contains a fix for this issue.
For tiff versions prior to 4.0.2-r1, update to version 4.0.2-r1 or later.
For libtiff4, libtiff4-dev, libtiff-opengl, libtiff-doc, libtiffxx0c2, and libtiff-tools, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Libtiff
Libtiff-Devel
Libtiff-Doc
Libtiff-Opengl
Libtiff-Tools
Libtiff4
Libtiff4-Dev
Libtiffxx0C2
Tiff