CVE-2009-2285: Buffer Overflow
Published Jul 1, 2009
·Updated
Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.
Affected Software
1 affected component
LibTIFF libtiff=3.8.2
Event History
Jul 1, 2009
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2285?
CVE-2009-2285 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2009-2285?
To address CVE-2009-2285, upgrade libtiff to a version later than 3.8.2.
3
What software is affected by CVE-2009-2285?
CVE-2009-2285 specifically affects libtiff version 3.8.2.
4
Can CVE-2009-2285 be exploited remotely?
Yes, CVE-2009-2285 can be exploited by context-dependent attackers through crafted TIFF images.
5
What type of vulnerability is CVE-2009-2285?
CVE-2009-2285 is a buffer underflow vulnerability that can result in application crashes.