CVE-2006-3463

Publication date 3 August 2006

Last updated 24 July 2024


Ubuntu priority

The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, which allows context-dependent attackers to cause a denial of service via a large td_nstrips value, which triggers an infinite loop.

Status

Package Ubuntu Release Status
tiff 7.04 feisty
Fixed 3.8.2-6
6.10 edgy
Fixed 3.8.2-6
6.06 LTS dapper
Fixed 3.7.4-1ubuntu3.2

References

Related Ubuntu Security Notices (USN)

    • USN-330-1
    • tiff vulnerabilities
    • 3 August 2006

Other references