First published: Mon Jun 07 2010(Updated: )
Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF file that triggers a buffer overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
tiff | =3.4-beta29 | |
tiff | =3.7.0-beta | |
tiff | =3.6.0-beta2 | |
tiff | =3.4-beta34 | |
tiff | =3.6.1 | |
tiff | =3.6.0-beta | |
tiff | =3.8.0 | |
tiff | =3.7.3 | |
tiff | =3.4-beta32 | |
tiff | =3.4-beta31 | |
tiff | =3.8.1 | |
tiff | =3.4-beta36 | |
tiff | =3.4-beta24 | |
tiff | =3.4 | |
tiff | =3.5.7-alpha4 | |
tiff | =3.8.2 | |
tiff | =3.4-beta28 | |
tiff | =3.5.7 | |
tiff | =3.5.7-beta | |
tiff | =3.7.2 | |
tiff | =3.4-beta37 | |
tiff | =3.7.0 | |
tiff | =3.6.0 | |
tiff | =3.5.3 | |
tiff | =3.7.1 | |
tiff | =3.5.4 | |
tiff | =3.5.2 | |
tiff | =3.5.7-alpha3 | |
tiff | =3.7.0-beta2 | |
tiff | =3.5.7-alpha | |
tiff | =3.7.4 | |
tiff | =3.7.0-alpha | |
tiff | =3.5.5 | |
tiff | =3.9.0-beta | |
tiff | =3.5.6-beta | |
tiff | =3.9.0 | |
tiff | =3.5.1 | |
tiff | =3.9.1 | |
tiff | =3.4-beta18 | |
tiff | =3.9 | |
tiff | =3.5.7-alpha2 | |
tiff | =3.5.6 | |
tiff | <=3.9.2 | |
tiff | =3.4-beta35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2065 is classified as a high severity vulnerability due to its potential to cause denial of service and possibly allow remote code execution.
To fix CVE-2010-2065, update LibTIFF to version 3.9.3 or later.
CVE-2010-2065 can enable remote attackers to execute arbitrary code or cause an application crash when processing crafted TIFF files.
LibTIFF versions prior to 3.9.3, including all versions 3.9.2 and below, are affected by CVE-2010-2065.
CVE-2010-2065 was reported by Sauli Pahlman of CERT-FI.