Lucene search

K
cve[email protected]CVE-2009-2347
HistoryJul 14, 2009 - 8:30 p.m.

CVE-2009-2347

2009-07-1420:30:00
CWE-189
web.nvd.nist.gov
52
cve-2009-2347
integer overflows
libtiff
arbitrary code execution
tiff image
vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.4%

Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.

Affected configurations

NVD
Node
libtifflibtiffMatch3.8.0
OR
libtifflibtiffMatch3.8.1
OR
libtifflibtiffMatch3.8.2
OR
libtifflibtiffMatch3.9
OR
libtifflibtiffMatch4.0

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.4%