CVE-2010-2630

The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libtiff:libtiff:3.9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:17

Type Values Removed Values Added
References () http://bugzilla.maptools.org/show_bug.cgi?id=2210 - Patch () http://bugzilla.maptools.org/show_bug.cgi?id=2210 - Patch
References () http://secunia.com/advisories/50726 - () http://secunia.com/advisories/50726 -
References () http://security.gentoo.org/glsa/glsa-201209-02.xml - () http://security.gentoo.org/glsa/glsa-201209-02.xml -
References () http://www.debian.org/security/2012/dsa-2552 - () http://www.debian.org/security/2012/dsa-2552 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=554371 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=554371 - Patch

Information

Published : 2010-07-06 17:17

Updated : 2025-04-11 00:51


NVD link : CVE-2010-2630

Mitre link : CVE-2010-2630

CVE.ORG link : CVE-2010-2630


JSON object : View

Products Affected

libtiff

  • libtiff
CWE
CWE-20

Improper Input Validation