CVE-2006-2024: Medium severity libtiff libtiff vulnerability
Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tifdirread.c; (2) certain "codec cleanup methods" in (b) tiflzw.c, (c) tifpixarlog.c, and (d) tifzip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tifjpeg.c, tifpixarlog.c, (f) tiffax3.c, and tifzip.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2024?
CVE-2006-2024 is considered a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2006-2024?
To fix CVE-2006-2024, update libtiff to version 3.8.1 or later.
What impact does CVE-2006-2024 have on affected systems?
CVE-2006-2024 can lead to denial of service on systems processing malicious TIFF images.
Which versions of libtiff are affected by CVE-2006-2024?
CVE-2006-2024 affects all versions of libtiff prior to 3.8.1.
What components of libtiff are vulnerable in CVE-2006-2024?
CVE-2006-2024 affects the TIFFFetchAnyArray function and certain codec cleanup methods in various .c files.