CVE-2010-1411
published 2010-06-17CVE-2010-1411: Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X…
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
12.85%
95.9th percentile
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| debian | tiff | < tiff 3.9.4-1 (bookworm) | tiff 3.9.4-1 (bookworm) |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tiff vulnerabilities
vendor_ubuntu·2010-06-21·CVSS 6.8
CVE-2010-1411 [MEDIUM] tiff vulnerabilities
Title: tiff vulnerabilities
Summary: Multiple integer overflows leading to crashes or arbitrary code execution.
Kevin Finisterre discovered that the TIFF library did not correctly handle
certain image structures. If a user or automated system were tricked
into opening a specially crafted TIFF image, a remote attacker could
execute arbitrary code with user privileges, or crash the application,
leading to a denial of service. (CVE-2010-1411)
Dan Rosenberg and Sauli Pahlman discovered multiple flaws in the TIFF
library. If a user or automated system were into opening a specially
crafted TIFF image, a remote attacker could execute arbitrary code
with user privileges, or crash the application, leading to a denial
of service. (Only Ubuntu 10.04 LTS was affected.) (CVE-2010-2065,
CVE-2010-2067
Red Hat
libtiff: integer overflows leading to heap overflow in Fax3SetupState
vendor_redhat·2010-06-14·CVSS 6.8
CVE-2010-1411 [MEDIUM] CWE-190 libtiff: integer overflows leading to heap overflow in Fax3SetupState
libtiff: integer overflows leading to heap overflow in Fax3SetupState
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
Package: libtiff (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-1411: tiff - Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the F...
vendor_debian·2010·CVSS 6.8
CVE-2010-1411 [MEDIUM] CVE-2010-1411: tiff - Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the F...
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 3.9.4-1)
bullseye: resolved (fixed in 3.9.4-1)
forky: resolved (fixed in 3.9.4-1)
sid: resolved (fixed in 3.9.4-1)
trixie: resolved (fixed in 3.9.4-1)
GHSA
GHSA-83rf-qxj4-9458: Multiple integer overflows in the Fax3SetupState function in tif_fax3
ghsa_unreviewed·2022-05-02
CVE-2010-1411 [MEDIUM] GHSA-83rf-qxj4-9458: Multiple integer overflows in the Fax3SetupState function in tif_fax3
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
OSV
CVE-2010-1411: Multiple integer overflows in the Fax3SetupState function in tif_fax3
osv·2010-06-17·CVSS 6.8
CVE-2010-1411 [MEDIUM] CVE-2010-1411: Multiple integer overflows in the Fax3SetupState function in tif_fax3
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/043769.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/043835.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://marc.info/?l=oss-security&m=127731610612908&w=2http://secunia.com/advisories/40181http://secunia.com/advisories/40196http://secunia.com/advisories/40220http://secunia.com/advisories/40381http://secunia.com/advisories/40478http://secunia.com/advisories/40527http://secunia.com/advisories/40536http://secunia.com/advisories/50726http://security.gentoo.org/glsa/glsa-201209-02.xmlhttp://securitytracker.com/id?1024103http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.596424http://support.apple.com/kb/HT4188http://support.apple.com/kb/HT4196http://support.apple.com/kb/HT4220http://www.redhat.com/support/errata/RHSA-2010-0519.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0520.htmlhttp://www.remotesensing.org/libtiff/v3.9.3.htmlhttp://www.securityfocus.com/bid/40823http://www.ubuntu.com/usn/USN-954-1http://www.vupen.com/english/advisories/2010/1435http://www.vupen.com/english/advisories/2010/1481http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2010/1638http://www.vupen.com/english/advisories/2010/1731http://www.vupen.com/english/advisories/2010/1761https://bugzilla.redhat.com/show_bug.cgi?id=592361http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/043769.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/043835.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://marc.info/?l=oss-security&m=127731610612908&w=2http://secunia.com/advisories/40181http://secunia.com/advisories/40196http://secunia.com/advisories/40220http://secunia.com/advisories/40381http://secunia.com/advisories/40478http://secunia.com/advisories/40527http://secunia.com/advisories/40536http://secunia.com/advisories/50726http://security.gentoo.org/glsa/glsa-201209-02.xmlhttp://securitytracker.com/id?1024103http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.596424http://support.apple.com/kb/HT4188http://support.apple.com/kb/HT4196http://support.apple.com/kb/HT4220http://www.redhat.com/support/errata/RHSA-2010-0519.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0520.htmlhttp://www.remotesensing.org/libtiff/v3.9.3.htmlhttp://www.securityfocus.com/bid/40823http://www.ubuntu.com/usn/USN-954-1http://www.vupen.com/english/advisories/2010/1435http://www.vupen.com/english/advisories/2010/1481http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2010/1638http://www.vupen.com/english/advisories/2010/1731http://www.vupen.com/english/advisories/2010/1761https://bugzilla.redhat.com/show_bug.cgi?id=592361
2010-06-17
Published