Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2443
HistoryJun 24, 2010 - 12:00 a.m.

CVE-2010-2443

2010-06-2400:00:00
ubuntu.com
ubuntu.com
9

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.051 Low

EPSS

Percentile

93.0%

The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3
allows remote attackers to cause a denial of service (NULL pointer
dereference and application crash) via an OJPEG image with undefined strip
offsets, related to the TIFFVGetField function.

Bugs

Notes

Author Note
mdeslaur lucid was fixed in same patch as CVE-2010-2065
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchtiff< 3.9.2-2ubuntu0.3UNKNOWN

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.051 Low

EPSS

Percentile

93.0%