Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Camimages | Gallium.inria | 2.2 (including) | 2.2 (including) |
| Advi | Ubuntu | dapper | * |
| Advi | Ubuntu | hardy | * |
| Advi | Ubuntu | intrepid | * |
| Advi | Ubuntu | jaunty | * |
| Advi | Ubuntu | karmic | * |
| Advi | Ubuntu | upstream | * |
| Camlimages | Ubuntu | dapper | * |
| Camlimages | Ubuntu | hardy | * |
| Camlimages | Ubuntu | intrepid | * |
| Camlimages | Ubuntu | jaunty | * |
| Camlimages | Ubuntu | karmic | * |
| Camlimages | Ubuntu | upstream | * |