CVE Reference: CVE-2010-2233

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-2233

Description:
tif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used in ImageMagick, does not properly perform vertical flips, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF image, related to "downsampled OJPEG input."

CVE Status:
Candidate

References:

ST
  1024150

SAID
  Secunia Advisory: SA40422
  Secunia Advisory: SA50726

MLIST
  http://marc.info/?l=oss-security&m=127731610612908&w=2

MISC
  http://www.remotesensing.org/libtiff/v3.9.4.html

GENTOO
  http://security.gentoo.org/glsa/glsa-201209-02.xml

CONFIRM
  http://bugzilla.maptools.org/show_bug.cgi?id=2207


Return to the previous page.