CVE-2010-2595: Input Validation
The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers an array index error, related to "downsampled OJPEG input."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2595?
CVE-2010-2595 is considered to have a moderate severity due to its ability to cause a denial of service through application crashes.
How do I fix CVE-2010-2595?
To fix CVE-2010-2595, upgrade LibTIFF to version 3.9.3 or later, which addresses the vulnerability.
What software is affected by CVE-2010-2595?
CVE-2010-2595 affects LibTIFF versions 3.9.0 and 3.9.2 as used in applications like ImageMagick.
Is there a risk of exploitation with CVE-2010-2595?
Yes, CVE-2010-2595 can be exploited by an attacker sending a specially crafted TIFF image that may lead to application crashes.
What type of vulnerability is CVE-2010-2595?
CVE-2010-2595 is a denial of service vulnerability caused by improper handling of invalid ReferenceBlackWhite values in TIFF images.