CVE Vulnerabilities

CVE-2009-3296

Published: Oct 20, 2009 | Modified: Oct 21, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.

Affected Software

Name Vendor Start Version End Version
Camimages Gallium.inria 2.2 (including) 2.2 (including)
Advi Ubuntu dapper *
Advi Ubuntu hardy *
Advi Ubuntu intrepid *
Advi Ubuntu jaunty *
Advi Ubuntu karmic *
Advi Ubuntu upstream *
Camlimages Ubuntu dapper *
Camlimages Ubuntu hardy *
Camlimages Ubuntu intrepid *
Camlimages Ubuntu jaunty *
Camlimages Ubuntu karmic *
Camlimages Ubuntu upstream *

References