Lucene search

K
cve[email protected]CVE-2006-3462
HistoryAug 03, 2006 - 1:04 a.m.

CVE-2006-3462

2006-08-0301:04:00
CWE-119
web.nvd.nist.gov
39
cve-2006-3462
buffer overflow
next
rle decoder
libtiff
security vulnerability
tiff library

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.6%

Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors involving decoding large RLE images.

Affected configurations

NVD
Node
libtifflibtiffRangeโ‰ค3.8.1
CPENameOperatorVersion
libtiff:libtifflibtiffle3.8.1

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.6%