CVE-2006-3460
Heap-based buffer overflow in the JPEG decoder in the TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an encoded JPEG stream that is longer than the scan line…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in the JPEG decoder in the TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an encoded JPEG stream that is longer than the scan line size (TiffScanLineSize).
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.42% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- libtiff/libtiff
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://lwn.net/Alerts/194228/
- http://secunia.com/advisories/21274Vendor Advisory
- http://secunia.com/advisories/21290Vendor Advisory
- http://secunia.com/advisories/21304Vendor Advisory
- http://secunia.com/advisories/21319Vendor Advisory
- http://secunia.com/advisories/21334Vendor Advisory
- http://secunia.com/advisories/21338Vendor Advisory
- http://secunia.com/advisories/21346Vendor Advisory
- http://secunia.com/advisories/21370Vendor Advisory
- http://secunia.com/advisories/21392Vendor Advisory
- http://secunia.com/advisories/21501Vendor Advisory
- http://secunia.com/advisories/21537Vendor Advisory
- http://secunia.com/advisories/21598Vendor Advisory
- http://secunia.com/advisories/21632Vendor Advisory
- http://secunia.com/advisories/22036Vendor Advisory
- http://secunia.com/advisories/27181Vendor Advisory
- http://secunia.com/advisories/27222Vendor Advisory
- http://secunia.com/advisories/27832Vendor Advisory
- http://securitytracker.com/id?1016628
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.536600
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103160-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201331-1
- http://support.avaya.com/elmodocs2/security/ASA-2006-166.htm
- http://www.debian.org/security/2006/dsa-1137Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200608-07.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:136
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:137
- http://www.novell.com/linux/security/advisories/2006_44_libtiff.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.