CVE-2010-4665: Integer Overflow
Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.
Other sources
The libtiff utility tiffdump contains an integer overflow which can be triggered when operating in a directory containing a large number of files.
Upstream bug: http://bugzilla.maptools.org/showbug.cgi?id=2218
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4665?
CVE-2010-4665 has a severity rating that indicates it can lead to application crashes and potential denial of service.
How do I fix CVE-2010-4665?
To fix CVE-2010-4665, update to LibTIFF version 3.9.5 or later.
What causes CVE-2010-4665?
CVE-2010-4665 is caused by an integer overflow in the ReadDirectory function when processing crafted TIFF files.
Which versions of LibTIFF are affected by CVE-2010-4665?
CVE-2010-4665 affects LibTIFF versions prior to 3.9.5, including all versions up to 3.9.4.
Can CVE-2010-4665 be exploited remotely?
Yes, CVE-2010-4665 can be exploited remotely through the use of specially crafted TIFF files.