MEDIUM
libtiff: OJPEGReadBufferFill NULL deref crash
Published Jul 6, 2010
4.3
MEDIUMCVSS 2.0
EPSS 8.77%
Description
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.
Affected products
No data.
OR
- ≤ 3.9.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.6
- 3.5.7
- 3.5.7
- 3.5.7
- 3.5.7
- 3.5.7
- 3.5.7
- 3.6.0
- 3.6.0
- 3.6.0
- 3.6.1
- 3.7.0
- 3.7.0
- 3.7.0
- 3.7.0
- 3.7.1
- 3.7.2
- 3.7.3
- 3.7.4
- 3.8.0
- 3.8.1
- 3.8.2
- 3.9.0
- 3.9.0
- 3.9.1
- 3.9.2
- 3.9.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of libtiff as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Weaknesses (1)
References (16)
- http://bugzilla.maptools.org/show_bug.cgi?id=1996 x_refsource_CONFIRM
- http://marc.info/?l=oss-security&m=127736307002102&w=2 mailing-listx_refsource_MLIST
- http://marc.info/?l=oss-security&m=127738540902757&w=2 mailing-listx_refsource_MLIST
- http://marc.info/?l=oss-security&m=127797353202873&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/40422 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/50726 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201209-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2012/dsa-2552 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2010/06/30/22 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2010-2482 Vendor Advisory
- https://bugs.launchpad.net/bugs/597246 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=603024 x_refsource_CONFIRMExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=608010 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-2488 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-2482
- https://www.cve.org/CVERecord?id=CVE-2010-2482
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 6, 2010
Updated Aug 7, 2024
Reserved Jun 28, 2010
Link CVE-2010-2482
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-2488 Assigner redhat
Published Jul 6, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-2488