Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-2193

Опубликовано: 08 июн. 2006
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 7.5

Описание

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

РелизСтатусПримечание
dapper

released

3.7.4-1ubuntu3.2
devel

released

3.8.2-6
edgy

released

3.8.2-6
feisty

released

3.8.2-6
upstream

needs-triage

Показывать по

EPSS

Процентиль: 66%
0.00527
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
около 19 лет назад

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

nvd
около 19 лет назад

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

debian
около 19 лет назад

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in li ...

github
около 3 лет назад

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

fstec
почти 19 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 66%
0.00527
Низкий

7.5 High

CVSS2