bugzilla.maptools.orgConfirmation
http://bugzilla.maptools.org/show_bug.cgi?id=2210 CVE-2010-2631
LibTIFF 3.9.4 - Unknown Tag Second Pass Processing Remote Denial of Service
Record summary
CVE-2010-2631 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLibTIFF 3.9.4 - Unknown Tag Second Pass Processing Remote Denial of ServiceExploitDB exploitby Tom LaneNot analyzed1 file
References
450726Third-party advisory
http://secunia.com/advisories/50726 GLSA-201209-02Vendor advisory
http://security.gentoo.org/glsa/glsa-201209-02.xml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-2631