Novell Home

CVE-2010-2067

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2010-2067 at MITRE

Description

Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long EXIF SubjectDistance field in a TIFF file.

NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 612787, 612879

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.3
  • tiff-debuginfo >= 3.9.2-5.1.1
  • tiff-debugsource >= 3.9.2-5.1.1
openSUSE 11.3
  • tiff >= 3.9.2-5.1.1

© 2014 Novell