PT-2010-5608 · Sam Leffler+1 · Libtiff-Tools+9

Published

1970-01-01

·

Updated

2013-05-15

·

CVE-2010-1411

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libtiff-devel-3.5.7 tiff versions prior to 4.0.2-r1 libtiff4 (affected versions not specified) libtiff4-dev (affected versions not specified) libtiff-opengl (affected versions not specified) libtiff-doc (affected versions not specified) libtiffxx0c2 (affected versions not specified) libtiff-tools (affected versions not specified)
Description The issue involves multiple vulnerabilities in the libtiff package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The Fax3SetupState function in tif fax3.c in the FAX3 decoder in LibTIFF is affected by multiple integer overflows, allowing remote attackers to execute arbitrary code or cause a denial of service via a crafted TIFF file.
Recommendations For libtiff-devel-3.5.7, update to a version that contains a fix for this issue. For tiff versions prior to 4.0.2-r1, update to version 4.0.2-r1 or later. For libtiff4, libtiff4-dev, libtiff-opengl, libtiff-doc, libtiffxx0c2, and libtiff-tools, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00789
BDU:2015-00790
BDU:2015-00791
BDU:2015-00792
BDU:2015-02008
BDU:2015-02009
BDU:2015-06342
BDU:2015-08600
BDU:2015-09646
CVE-2010-1411
DSA-2084-1
RHSA-2010:0519
RHSA-2010:0520
RHSA-2010_0519

Affected Products

Red Hat
Libtiff
Libtiff-Devel
Libtiff-Doc
Libtiff-Opengl
Libtiff-Tools
Libtiff4
Libtiff4-Dev
Libtiffxx0C2
Tiff