CVE-2010-2481: Buffer Overflow
The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2481?
CVE-2010-2481 has a severity rating that allows remote attackers to cause denial of service.
How do I fix CVE-2010-2481?
To fix CVE-2010-2481, you should upgrade to LibTIFF version 3.9.4 or later.
What versions of LibTIFF are affected by CVE-2010-2481?
CVE-2010-2481 affects LibTIFF versions prior to 3.9.4, including several beta and release versions.
What type of vulnerability is CVE-2010-2481?
CVE-2010-2481 is a denial-of-service vulnerability caused by improper handling of unknown tag types in TIFF files.
Can CVE-2010-2481 lead to data loss?
While CVE-2010-2481 primarily causes application crashes, it can potentially lead to data loss depending on the application's state at the time of the crash.