Back

HIGH

tiffsplit buffer overflow

Published May 30, 2006

Description

Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 30, 2006
Updated Aug 7, 2024
Reserved May 30, 2006
NVD
Status Modified
Modified Sep 23, 2026
Red Hat
Severity Low
Public date May 25, 2006