CVE-2010-2443: Null Pointer Dereference
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2443 to the following vulnerability:
Unspecified vulnerability in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) via an OJPEG image with undefined strip offsets.
References: http://www.remotesensing.org/libtiff/v3.9.3.html
Other sources
The OJPEGReadBufferFill function in tifojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2443?
The severity of CVE-2010-2443 is classified as low to moderate, primarily due to its potential for denial of service.
How do I fix CVE-2010-2443?
To fix CVE-2010-2443, users should upgrade to LibTIFF version 3.9.3 or later.
Which versions of LibTIFF are affected by CVE-2010-2443?
CVE-2010-2443 affects LibTIFF versions prior to 3.9.3, including various beta releases and stable versions.
What type of vulnerability is CVE-2010-2443?
CVE-2010-2443 is a denial of service vulnerability that can cause an application crash.
Can CVE-2010-2443 be exploited remotely?
Yes, CVE-2010-2443 can be exploited by remote attackers to trigger a denial of service condition.