LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to cause a denial of service via a crafted TIFF image, related to "downsampled OJPEG input."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1761 | vdb entry broken link |
http://www.redhat.com/support/errata/RHSA-2010-0520.html | vendor advisory not applicable |
http://secunia.com/advisories/40536 | third party advisory permissions required |
https://bugzilla.redhat.com/show_bug.cgi?id=583081 | exploit |