Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-2597

Опубликовано: 02 июл. 2010
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

РелизСтатусПримечание
dapper

released

3.7.4-1ubuntu3.9
devel

released

3.9.4-5ubuntu2
hardy

released

3.8.2-7ubuntu3.7
jaunty

ignored

end of life
karmic

released

3.8.2-13ubuntu0.4
lucid

released

3.9.2-2ubuntu0.4
maverick

released

3.9.4-2ubuntu0.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 87%
0.03306
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 15 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

nvd
почти 15 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

debian
почти 15 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 ...

github
около 3 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

oracle-oval
почти 15 лет назад

ELSA-2010-0519: libtiff security update (IMPORTANT)

EPSS

Процентиль: 87%
0.03306
Низкий

4.3 Medium

CVSS2