Lucene search

K
cve[email protected]CVE-2010-2443
HistoryJun 24, 2010 - 5:30 p.m.

CVE-2010-2443

2010-06-2417:30:01
web.nvd.nist.gov
28
libtiff
cve-2010-2443
ojpegreadbufferfill
denial of service
remote attackers
null pointer dereference

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

8.8 High

AI Score

Confidence

High

0.05 Low

EPSS

Percentile

92.9%

The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function.

Affected configurations

NVD
Node
libtifflibtiffRange3.9.2
OR
libtifflibtiffMatch3.4
OR
libtifflibtiffMatch3.4beta18
OR
libtifflibtiffMatch3.4beta24
OR
libtifflibtiffMatch3.4beta28
OR
libtifflibtiffMatch3.4beta29
OR
libtifflibtiffMatch3.4beta31
OR
libtifflibtiffMatch3.4beta32
OR
libtifflibtiffMatch3.4beta34
OR
libtifflibtiffMatch3.4beta35
OR
libtifflibtiffMatch3.4beta36
OR
libtifflibtiffMatch3.4beta37
OR
libtifflibtiffMatch3.5.1
OR
libtifflibtiffMatch3.5.2
OR
libtifflibtiffMatch3.5.3
OR
libtifflibtiffMatch3.5.4
OR
libtifflibtiffMatch3.5.5
OR
libtifflibtiffMatch3.5.6
OR
libtifflibtiffMatch3.5.6beta
OR
libtifflibtiffMatch3.5.7
OR
libtifflibtiffMatch3.5.7alpha
OR
libtifflibtiffMatch3.5.7alpha2
OR
libtifflibtiffMatch3.5.7alpha3
OR
libtifflibtiffMatch3.5.7alpha4
OR
libtifflibtiffMatch3.5.7beta
OR
libtifflibtiffMatch3.6.0
OR
libtifflibtiffMatch3.6.0beta
OR
libtifflibtiffMatch3.6.0beta2
OR
libtifflibtiffMatch3.6.1
OR
libtifflibtiffMatch3.7.0
OR
libtifflibtiffMatch3.7.0alpha
OR
libtifflibtiffMatch3.7.0beta
OR
libtifflibtiffMatch3.7.0beta2
OR
libtifflibtiffMatch3.7.1
OR
libtifflibtiffMatch3.7.2
OR
libtifflibtiffMatch3.7.3
OR
libtifflibtiffMatch3.7.4
OR
libtifflibtiffMatch3.8.0
OR
libtifflibtiffMatch3.8.1
OR
libtifflibtiffMatch3.8.2
OR
libtifflibtiffMatch3.9
OR
libtifflibtiffMatch3.9.0
OR
libtifflibtiffMatch3.9.0beta
OR
libtifflibtiffMatch3.9.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

8.8 High

AI Score

Confidence

High

0.05 Low

EPSS

Percentile

92.9%