Vulnerability Description
Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libtiff | Libtiff | <= 3.8.1 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
- http://lwn.net/Alerts/194228/
- http://secunia.com/advisories/21253
- http://secunia.com/advisories/21274
- http://secunia.com/advisories/21290
- http://secunia.com/advisories/21304
- http://secunia.com/advisories/21319
- http://secunia.com/advisories/21334
- http://secunia.com/advisories/21338
- http://secunia.com/advisories/21346
- http://secunia.com/advisories/21370
- http://secunia.com/advisories/21392
- http://secunia.com/advisories/21501
FAQ
What is CVE-2006-3461?
CVE-2006-3461 is a vulnerability with a CVSS score of 7.5 (HIGH). Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.
How severe is CVE-2006-3461?
CVE-2006-3461 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3461?
Check the references section above for vendor advisories and patch information. Affected products include: Libtiff Libtiff.