CVE-2010-2482: Null Pointer Dereference
LibTIFF 3.9.4 and earlier does not properly handle an invalid tdstripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2482?
CVE-2010-2482 has been classified as a denial-of-service vulnerability due to a NULL pointer dereference that can crash the application.
How do I fix CVE-2010-2482?
To mitigate CVE-2010-2482, upgrade to a version of LibTIFF that is greater than 3.9.4.
What types of attacks can exploit CVE-2010-2482?
CVE-2010-2482 can be exploited by attackers sending specially crafted TIFF files to the affected application.
Which versions of LibTIFF are affected by CVE-2010-2482?
LibTIFF versions 3.9.4 and earlier are affected by CVE-2010-2482.
What is the impact of CVE-2010-2482 on affected systems?
The impact of CVE-2010-2482 is a denial of service, causing the affected application to crash when processing malformed TIFF files.