Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-2482NULL Pointer Dereference in Tiff

Severity
4.3MEDIUMNVD
OSV5.0
EPSS
18.8%
top 4.69%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 6
Latest updateMay 17

Description

LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDlibtiff/libtiff3.9.4+22
debiandebian/tiff< tiff 3.9.4-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-mr66-pfm6-xmq6: LibTIFF 32022-05-17
OSV
CVE-2010-2482: LibTIFF 32010-07-06

💥Exploits & PoCs

1
Exploit-DB
LibTIFF - 'td_stripbytecount' Null Pointer Dereference Remote Denial of Service2010-08-07

📋Vendor Advisories

4
Ubuntu
tiff regression2011-03-15
Ubuntu
tiff vulnerabilities2011-03-07
Red Hat
libtiff: OJPEGReadBufferFill NULL deref crash2010-06-15
Debian
CVE-2010-2482: tiff - LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount ...2010

💬Community

1
Bugzilla
CVE-2010-2443 CVE-2010-2482 libtiff: OJPEGReadBufferFill NULL deref crash2010-06-25