Vulnerability Description
Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libtiff | Libtiff | <= 3.8.0 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
- http://bugzilla.remotesensing.org/show_bug.cgi?id=1102ExploitPatch
- http://secunia.com/advisories/19838
- http://secunia.com/advisories/19897
- http://secunia.com/advisories/19936
- http://secunia.com/advisories/19949
- http://secunia.com/advisories/19964
- http://secunia.com/advisories/20021
- http://secunia.com/advisories/20023
- http://secunia.com/advisories/20210
- http://secunia.com/advisories/20345
- http://secunia.com/advisories/20667
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1
- http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm
FAQ
What is CVE-2006-2025?
CVE-2006-2025 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a craft...
How severe is CVE-2006-2025?
CVE-2006-2025 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-2025?
Check the references section above for vendor advisories and patch information. Affected products include: Libtiff Libtiff.