CVE-2010-2597: Input Validation
The TIFFVStripSize function in tifstrip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2597?
CVE-2010-2597 has a severity rating indicating a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2010-2597?
To fix CVE-2010-2597, upgrade LibTIFF to version 3.9.3 or later where this vulnerability has been addressed.
Who is affected by CVE-2010-2597?
CVE-2010-2597 affects users of LibTIFF versions 3.9.0 and 3.9.2.
What type of vulnerability is CVE-2010-2597?
CVE-2010-2597 is classified as a denial of service vulnerability caused by improper handling of TIFF images.
Can CVE-2010-2597 be exploited remotely?
Yes, CVE-2010-2597 can be exploited remotely by attackers through crafted TIFF image files.