2.1
CVSSv2

CVE-2006-2120

Published: 01/05/2006 Updated: 03/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The TIFFToRGB function in libtiff prior to 3.8.1 allows remote malicious users to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 3.8.1

Vendor Advisories

Debian Bug report logs - #366588 CVE-2006-2120: denial of service (crash) via a crafted TIFF image Package: libtiff4; Maintainer for libtiff4 is (unknown); Reported by: Stefan Fritsch <sf@sfritschde> Date: Tue, 9 May 2006 19:33:04 UTC Severity: grave Tags: security Found in version libtiff4/372-3sarge1 Fixed in versio ...
Tavis Ormandy and Andrey Kiselev discovered that libtiff did not sufficiently verify the validity of TIFF files By tricking an user into opening a specially crafted TIFF file with any application that uses libtiff, an attacker could exploit this to crash the application or even execute arbitrary code with the application’s privileges ...
Andrey Kiselev discovered a problem in the TIFF library that may allow an attacker with a specially crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values to crash the library and hence the surrounding application The old stable distribution (woody) is not affected by this problem For the stable distribution (sarge) this probl ...