Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1835-1 | New tiff packages fix several vulnerabilities |
EUVD |
EUVD-2009-2343 | Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr. |
Ubuntu USN |
USN-801-1 | tiff vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:44:55.963Z
Reserved: 2009-07-07T00:00:00
Link: CVE-2009-2347
No data.
Status : Deferred
Published: 2009-07-14T20:30:00.377
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2347
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN