4
CVSSv2

CVE-2006-2024

Published: 25/04/2006 Updated: 03/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Multiple vulnerabilities in libtiff prior to 3.8.1 allow context-dependent malicious users to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 3.5.6

libtiff libtiff 3.5.7

libtiff libtiff 3.5.4

libtiff libtiff 3.5.5

libtiff libtiff

libtiff libtiff 3.4

libtiff libtiff 3.6.0

libtiff libtiff 3.6.1

libtiff libtiff 3.5.1

libtiff libtiff 3.5.2

libtiff libtiff 3.5.3

libtiff libtiff 3.7.0

libtiff libtiff 3.7.1

Vendor Advisories

Tavis Ormandy and Andrey Kiselev discovered that libtiff did not sufficiently verify the validity of TIFF files By tricking an user into opening a specially crafted TIFF file with any application that uses libtiff, an attacker could exploit this to crash the application or even execute arbitrary code with the application’s privileges ...
Tavis Ormandy discovered several vulnerabilities in the TIFF library that can lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-2024 Multiple vulnerabilities allow attackers to cause a denial of service CVE-2006-2025 An integer o ...

Exploits

source: wwwsecurityfocuscom/bid/17730/info LibTIFF is affected by multiple denial-of-service vulnerabilities An attacker can exploit these vulnerabilities to cause a denial of service in applications using the affected library githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/27762-1tiff0 gi ...