CVE-2010-4665Integer Overflow or Wraparound in Libtiff

Severity
4.3MEDIUMNVD
EPSS
2.3%
top 15.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 3
Latest updateMay 17

Description

Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDlibtiff/libtiff3.9.4+24
debiandebian/tiff

Patches

🔴Vulnerability Details

1
GHSA
GHSA-hvq6-mmrf-8v38: Integer overflow in the ReadDirectory function in tiffdump2022-05-17

📋Vendor Advisories

3
Ubuntu
tiff vulnerabilities2012-04-04
Red Hat
libtiff tiffdump integer overflow2010-06-22
Debian
CVE-2010-4665: tiff - Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibT...2010

💬Community

2
Bugzilla
CVE-2009-5022 CVE-2010-4665 libtiff various flaws [fedora-all]2011-04-13
Bugzilla
CVE-2010-4665 libtiff tiffdump integer overflow2011-04-12