CVE-2010-2065
Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF file that triggers a buffer overflow.
- Libtiff
- ≤ 3.9.2, 3.4, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.8.0, 3.8.1, 3.8.2, 3.9, 3.9.0, 3.9.1
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 5.6% (92th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2010-06-23
CVE-2010-2065 at NVD
1 known exploit for CVE-2010-2065
Proof-of-concept code and exploit modules indexed by Sploitus