CVE-2006-2120: Low severity LibTIFF libtiff vulnerability
Published May 1, 2006
·Updated
The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.
Affected Software
1 affected component
LibTIFF libtiff=3.8.1
Remediation
Patch Available
Patch Available
Event History
May 1, 2006
CVE Published
10:06 PM
May 2, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2120?
CVE-2006-2120 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2006-2120?
To fix CVE-2006-2120, upgrade the libtiff library to version 3.8.1 or later.
3
What types of attacks can exploit CVE-2006-2120?
CVE-2006-2120 can be exploited by remote attackers using crafted TIFF images to trigger crashes.
4
Which software is affected by CVE-2006-2120?
CVE-2006-2120 affects libtiff versions before 3.8.1.
5
What is the impact of exploiting CVE-2006-2120?
Exploiting CVE-2006-2120 results in an out-of-bounds read causing a denial of service.