Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Zero-Day Monitor
  Search Engine
 
   

>> LibTIFF Image Handling Multiple Buffer Overflow and Denial of Service Vulnerabilities

Title : LibTIFF Image Handling Multiple Buffer Overflow and Denial of Service Vulnerabilities
Advisory ID : VUPEN/ADV-2006-1563
CVE ID : CVE-2006-2024 - CVE-2006-2025 - CVE-2006-2026 - CVE-2006-2120
Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-04-28

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

Multiple vulnerabilities have been identified in LibTIFF, which could be exploited by attackers to execute arbitrary commands or cause a denial of service.

The first issue is due to buffer overflow errors in the "TIFFFetchAnyArray()" [tif_dirread.c] function and in certain cleanup methods and functions, which could be exploited by attackers to crash a vulnerable application via a malformed TIFF image [...]

Affected Products

LibTIFF version 3.8.0 and prior

Credits

Vulnerabilities reported by Tavis Ormandy

ChangeLog

2006-04-28 : Initial release
2006-05-03 : Additional Vulnerability

Vulnerability Management

Subscribe to VUPEN Security VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@vupen.com.

 


Copyright 2003-2008 © VUPEN.COM - Privacy Policy