5
CVSSv2

CVE-2006-0405

Published: 25/01/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote malicious users to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField function.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 3.8.0

Vendor Advisories

Debian Bug report logs - #350715 CVE-2006-0405: DoS through null pointer dereference Package: tiff; Maintainer for tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 31 Jan 2006 11:18:07 UTC Severity: important Tags: security Fixed in version tiff/380-2 ...