CVE-2006-3464: Integer Overflow
TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to pass numeric range checks and possibly execute code, and trigger assert errors, via large offset values in a TIFF directory that lead to an integer overflow and other unspecified vectors involving "unchecked arithmetic operations".
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3464?
CVE-2006-3464 has been classified as a high severity vulnerability due to its potential to allow code execution through integer overflow.
How do I fix CVE-2006-3464?
To fix CVE-2006-3464, update the libtiff library to version 3.8.2 or later.
What software is affected by CVE-2006-3464?
CVE-2006-3464 affects versions of the libtiff library prior to 3.8.2.
Can CVE-2006-3464 be exploited remotely?
Yes, attackers can exploit CVE-2006-3464 remotely by crafting malicious TIFF files.
What are the potential impacts of CVE-2006-3464?
The potential impacts of CVE-2006-3464 include application crashes and arbitrary code execution.