CVE Reference: CVE-2010-2482

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-2482

Description:
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA40422
  Secunia Advisory: SA50726

MLIST
  http://marc.info/?l=oss-security&m=127797353202873&w=2
  http://www.openwall.com/lists/oss-security/2010/06/30/22
  http://marc.info/?l=oss-security&m=127736307002102&w=2
  http://marc.info/?l=oss-security&m=127738540902757&w=2

GENTOO
  http://security.gentoo.org/glsa/glsa-201209-02.xml

DEBIAN
  http://www.debian.org/security/2012/dsa-2552

CONFIRM
  http://bugzilla.maptools.org/show_bug.cgi?id=1996


Return to the previous page.