CVE-2010-2481
Publication date 6 July 2010
Last updated 24 July 2024
Ubuntu priority
The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.
Notes
mdeslaur
see CVE-2010-2630 for second commit to fix regression in lucid, this is the fix-unknown-tags.patch patch