CVE-2006-3459: Buffer Overflow
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdircount value in the TIFFFetchShortPair function in tifdirread.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3459?
CVE-2006-3459 has a high severity rating due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2006-3459?
To fix CVE-2006-3459, upgrade the TIFF library (libtiff) to version 3.8.2 or later.
Which versions of libtiff are affected by CVE-2006-3459?
Versions of libtiff prior to 3.8.2, including all versions from 3.4 beta to 3.8.1, are affected by CVE-2006-3459.
Can Adobe Reader 9.3.0 be exploited due to CVE-2006-3459?
While Adobe Reader 9.3.0 utilizes the vulnerable libtiff, it is not directly affected since it uses a patched version.
What types of attacks can be executed using CVE-2006-3459?
CVE-2006-3459 can be exploited to execute arbitrary code or cause a denial of service through specially crafted TIFF files.