Oval Definition:oval:org.opensuse.security:def:20062656
Revision Date:2022-06-30Version:1
Title:CVE-2006-2656
Description:

Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2006-2656
Mitre CVE-2006-2656
SUSE CVE-2006-2656
SUSE-SR:2006:014
Platform(s):Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
openSUSE Tumbleweed
SUSE CORE 9 for AMD64 and Intel EM64T
SUSE CORE 9 for IBM POWER
SUSE CORE 9 for IBM S/390 31bit
SUSE CORE 9 for IBM zSeries 64bit
SUSE CORE 9 for Itanium Processor Family
SUSE CORE 9 for x86
Product(s):
Definition Synopsis
  • sles9-nld is installed
  • AND tiff less than 3.6.1-38.30
  • Definition Synopsis
  • core9 is installed
  • AND tiff less than 3.6.1-38.30
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • libtiff-devel-4.3.0-1.3 is installed
  • OR libtiff-devel-32bit-4.3.0-1.3 is installed
  • OR libtiff5-4.3.0-1.3 is installed
  • OR libtiff5-32bit-4.3.0-1.3 is installed
  • OR tiff-4.3.0-1.3 is installed
  • BACK