[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252097

 
 

909

 
 

196747

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2552-1 tiff -- several

ID: oval:org.secpod.oval:def:600893Date: (C)2012-10-02   (M)2023-02-20
Class: PATCHFamily: unix




Several vulnerabilities were discovered in Tiff, a library set and tools to support the Tag Image File Format , allowing denial of service and potential privilege escalation. These vulnerabilities can be exploited via a specially crafted TIFF image. CVE-2012-2113 The tiff2pdf utility has an integer overflow error when parsing images. CVE-2012-3401 Huzaifa Sidhpurwala discovered heap-based buffer overflow in the t2p_read_tiff_init function. CVE-2010-2482 An invalid td_stripbytecount field is not properly handle and can trigger a NULL pointer dereference. CVE-2010-2595 An array index error, related to "downsampled OJPEG input." in the TIFFYCbCrtoRGB function causes an unexpected crash. CVE-2010-2597 Also related to "downsampled OJPEG input", the TIFFVStripSize function crash unexpectly. CVE-2010-2630 The TIFFReadDirectory function does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file. CVE-2010-4665 The tiffdump utility has an integer overflow in the ReadDirectory function.

Platform:
Debian 6.0
Product:
libtiff4
Reference:
DSA-2552-1
CVE-2010-2482
CVE-2010-2595
CVE-2010-2597
CVE-2010-2630
CVE-2010-4665
CVE-2012-2113
CVE-2012-3401
CVE    7
CVE-2010-2597
CVE-2010-2630
CVE-2010-2595
CVE-2010-2482
...
CPE    2
cpe:/a:libtiff:libtiff4
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies