CVE Vulnerabilities

CVE-2009-3296

Published: Oct 20, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.

Affected Software

NameVendorStart VersionEnd Version
CamimagesGallium.inria2.2 (including)2.2 (including)
AdviUbuntudapper*
AdviUbuntuhardy*
AdviUbuntuintrepid*
AdviUbuntujaunty*
AdviUbuntukarmic*
AdviUbuntuupstream*
CamlimagesUbuntudapper*
CamlimagesUbuntuhardy*
CamlimagesUbuntuintrepid*
CamlimagesUbuntujaunty*
CamlimagesUbuntukarmic*
CamlimagesUbuntuupstream*

References