CVE-2006-0405: Null Pointer Dereference
Published Jan 25, 2006
·Updated
The TIFFFetchShortPair function in tifdirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField function.
Affected Software
1 affected component
LibTIFF libtiff=3.8.0
Event History
Jan 25, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0405?
CVE-2006-0405 is classified as a denial of service vulnerability.
2
How do I fix CVE-2006-0405?
The recommended fix for CVE-2006-0405 is to upgrade to libtiff version 3.8.1 or later.
3
Which versions of libtiff are affected by CVE-2006-0405?
CVE-2006-0405 affects libtiff version 3.8.0.
4
What type of attack does CVE-2006-0405 exploit?
CVE-2006-0405 exploits a NULL pointer dereference in the TIFFFetchShortPair function.
5
Can an attacker trigger CVE-2006-0405 remotely?
Yes, an attacker can trigger CVE-2006-0405 remotely by using a crafted TIFF image.