Lucene search

K
cve[email protected]CVE-2006-3464
HistoryAug 03, 2006 - 1:04 a.m.

CVE-2006-3464

2006-08-0301:04:00
CWE-189
web.nvd.nist.gov
42
cve-2006-3464
tiff library
libtiff
integer overflow
code execution
assert errors

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.022 Low

EPSS

Percentile

89.6%

TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to pass numeric range checks and possibly execute code, and trigger assert errors, via large offset values in a TIFF directory that lead to an integer overflow and other unspecified vectors involving โ€œunchecked arithmetic operationsโ€.

Affected configurations

NVD
Node
libtifflibtiffRangeโ‰ค3.8.1
CPENameOperatorVersion
libtiff:libtifflibtiffle3.8.1

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.022 Low

EPSS

Percentile

89.6%