CVE Vulnerabilities

CVE-2006-2024

Published: Apr 25, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain codec cleanup methods in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.

Affected Software

NameVendorStart VersionEnd Version
LibtiffLibtiff*3.8.0 (including)
LibtiffLibtiff3.4 (including)3.4 (including)
LibtiffLibtiff3.5.1 (including)3.5.1 (including)
LibtiffLibtiff3.5.2 (including)3.5.2 (including)
LibtiffLibtiff3.5.3 (including)3.5.3 (including)
LibtiffLibtiff3.5.4 (including)3.5.4 (including)
LibtiffLibtiff3.5.5 (including)3.5.5 (including)
LibtiffLibtiff3.5.6 (including)3.5.6 (including)
LibtiffLibtiff3.5.7 (including)3.5.7 (including)
LibtiffLibtiff3.6.0 (including)3.6.0 (including)
LibtiffLibtiff3.6.1 (including)3.6.1 (including)
LibtiffLibtiff3.7.0 (including)3.7.0 (including)
LibtiffLibtiff3.7.1 (including)3.7.1 (including)
Red Hat Enterprise Linux 3RedHatlibtiff-0:3.5.7-25.el3.1*
Red Hat Enterprise Linux 3RedHatkdegraphics-7:3.1.3-3.10*
Red Hat Enterprise Linux 4RedHatlibtiff-0:3.6.1-10*
TiffUbuntudapper*

References