6.5
CVSSv2

CVE-2006-2025

Published: 25/04/2006 Updated: 03/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff prior to 3.8.1 allows context-dependent malicious users to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 3.4

libtiff libtiff 3.5.1

libtiff libtiff 3.6.0

libtiff libtiff 3.6.1

libtiff libtiff 3.5.6

libtiff libtiff 3.5.7

libtiff libtiff 3.5.2

libtiff libtiff 3.5.3

libtiff libtiff 3.7.0

libtiff libtiff 3.7.1

libtiff libtiff

libtiff libtiff 3.5.4

libtiff libtiff 3.5.5

Vendor Advisories

Tavis Ormandy and Andrey Kiselev discovered that libtiff did not sufficiently verify the validity of TIFF files By tricking an user into opening a specially crafted TIFF file with any application that uses libtiff, an attacker could exploit this to crash the application or even execute arbitrary code with the application’s privileges ...
Tavis Ormandy discovered several vulnerabilities in the TIFF library that can lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-2024 Multiple vulnerabilities allow attackers to cause a denial of service CVE-2006-2025 An integer o ...

Exploits

source: wwwsecurityfocuscom/bid/17732/info Applications using the LibTIFF library are prone to an integer-overflow vulnerability An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application that uses the affected library Failed exploit attempts will likely cause denial-of-service c ...