First published: Wed Aug 03 2005(Updated: )
libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tiff | =3.6.1 | |
tiff | =3.5.7 | |
tiff | =3.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2452 is classified as a denial of service vulnerability that can cause application crashes.
To fix CVE-2005-2452, users should update to a version of libtiff later than 3.7.0, which addresses the vulnerability.
CVE-2005-2452 affects libtiff versions up to and including 3.7.0.
The vulnerability occurs due to a divide-by-zero error triggered by a TIFF image header with a zero 'YCbCr subsampling' value.
Yes, CVE-2005-2452 is a different issue than CVE-2004-0804, despite both being related to libtiff.