First published: Thu Jul 01 2010(Updated: )
The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers an array index error, related to "downsampled OJPEG input."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tiff | =3.9.0 | |
tiff | =3.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2595 is considered to have a moderate severity due to its ability to cause a denial of service through application crashes.
To fix CVE-2010-2595, upgrade LibTIFF to version 3.9.3 or later, which addresses the vulnerability.
CVE-2010-2595 affects LibTIFF versions 3.9.0 and 3.9.2 as used in applications like ImageMagick.
Yes, CVE-2010-2595 can be exploited by an attacker sending a specially crafted TIFF image that may lead to application crashes.
CVE-2010-2595 is a denial of service vulnerability caused by improper handling of invalid ReferenceBlackWhite values in TIFF images.