Vulnerability Name: | CVE-2010-2596 (CCN-60109) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2010-04-16 | ||||||||||||||||||||||||||||||||||||
Published: | 2010-04-16 | ||||||||||||||||||||||||||||||||||||
Updated: | 2013-05-15 | ||||||||||||||||||||||||||||||||||||
Summary: | The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and 3.9.2, as used in tiff2ps, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF image, related to "downsampled OJPEG input." | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
3.5 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||
References: | Source: CONFIRM Type: UNKNOWN http://bugzilla.maptools.org/show_bug.cgi?id=2209 Source: MITRE Type: CNA CVE-2010-2596 Source: MLIST Type: UNKNOWN [oss-security] 20100623 CVE requests: LibTIFF Source: CCN Type: RHSA-2014-0222 Moderate: libtiff security update Source: CCN Type: SA40422 LibTIFF Denial of Service Vulnerabilities Source: SECUNIA Type: UNKNOWN 40422 Source: SECUNIA Type: UNKNOWN 50726 Source: GENTOO Type: UNKNOWN GLSA-201209-02 Source: CCN Type: OSVDB ID: 65970 LibTIFF tif_ojpeg.c OJPEGPostDecode Function Downsampled OJPEG Input DoS Source: CCN Type: LibTIFF Web site LibTIFF - TIFF Library and Utilities Source: CCN Type: Red Hat Bugzilla Bug 583081 Assorted libtiff failures on downsampled OJPEG input Source: CONFIRM Type: Exploit https://bugzilla.redhat.com/show_bug.cgi?id=583081 Source: CCN Type: Red Hat Bugzilla Bug 603024 libtiff: OJPEGReadBufferFill() NULL pointer deref Source: XF Type: UNKNOWN libtiff-ojpegpostdecode-dos(60109) | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |