CVE-2006-2120Tiff vulnerability

7 documents7 sources
Severity
2.1LOWNVD
EPSS
0.3%
top 44.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateMay 3

Description

The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDlibtiff/libtiff3.8.1
debiandebian/tiff< tiff 3.8.1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vj46-9qg5-hvg2: The TIFFToRGB function in libtiff before 32022-05-03
OSV
CVE-2006-2120: The TIFFToRGB function in libtiff before 32006-05-01

📋Vendor Advisories

3
Ubuntu
TIFF library vulnerabilities2006-05-04
Red Hat
security flaw2006-02-08
Debian
CVE-2006-2120: tiff - The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause ...2006

💬Community

1
Bugzilla
CVE-2006-2120 security flaw2018-08-16