HIGH
Multiple libtiff flaws (CVE-2006-3460 CVE-2006-3461 CVE-2006-3462 CVE-2006-3463 CVE-2006-3464 CVE-2006-3465)
Published Aug 3, 2006
7.5
HIGHCVSS 2.0
EPSS 5.32%
Description
Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors involving decoding large RLE images.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
kdegraphics-7:3.1.3-3.10
Fixed · RHSA-2006:0648
Red Hat Enterprise Linux 3
libtiff-0:3.5.7-25.el3.4
Fixed · RHSA-2006:0603
Red Hat Enterprise Linux 4
libtiff-0:3.6.1-12
Fixed · RHSA-2006:0603
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | kdegraphics-7:3.1.3-3.10 | Fixed | RHSA-2006:0648 |
| Red Hat Enterprise Linux 3 | libtiff-0:3.5.7-25.el3.4 | Fixed | RHSA-2006:0603 |
| Red Hat Enterprise Linux 4 | libtiff-0:3.6.1-12 | Fixed | RHSA-2006:0603 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Weaknesses (1)
References (51)
- ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P vendor-advisoryx_refsource_SGI
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc vendor-advisoryx_refsource_SGI
- http://docs.info.apple.com/article.html?artnum=304063 x_refsource_MISC
- http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lwn.net/Alerts/194228/ vendor-advisoryx_refsource_TRUSTIX
- http://secunia.com/advisories/21253 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21274 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21290 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21304 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21319 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21334 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21338 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21346 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21370 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21392 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21501 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21537 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21598 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21632 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22036 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27181 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27222 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27832 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1016628 vdb-entryx_refsource_SECTRACK
- http://securitytracker.com/id?1016671 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.536600 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103160-1 vendor-advisoryx_refsource_SUNALERT
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201331-1 vendor-advisoryx_refsource_SUNALERT
- http://support.avaya.com/elmodocs2/security/ASA-2006-166.htm x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1137 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200608-07.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:136 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:137 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_44_libtiff.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/27726 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0603.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0648.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/bid/19282 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/19289 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-330-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA06-214A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/3101 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/3105 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/3486 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/4034 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-3462 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=199111 Issue Tracking
- https://issues.rpath.com/browse/RPL-558 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-3462
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11301 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-3462
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 3, 2006
Updated Aug 7, 2024
Reserved Jul 10, 2006
Link CVE-2006-3462
CISA Vulnrichment
Updated n/a