CVE-2010-2631: Input Validation
Published Jul 6, 2010
·Updated
LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
Affected Software
1 affected component
LibTIFF libtiff=3.9.0
Remediation
Patch Available
Event History
Jul 6, 2010
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2631?
CVE-2010-2631 has a severity rating that indicates it can lead to a denial of service by causing an application crash.
2
How do I fix CVE-2010-2631?
To fix CVE-2010-2631, you should update to a patched version of LibTIFF that addresses this vulnerability.
3
What versions of LibTIFF are affected by CVE-2010-2631?
CVE-2010-2631 specifically affects LibTIFF version 3.9.0.
4
Can CVE-2010-2631 be exploited remotely?
Yes, CVE-2010-2631 can be exploited remotely via crafted TIFF files.
5
What kind of attack is associated with CVE-2010-2631?
CVE-2010-2631 is associated with denial of service attacks that result in application crashes.