CVE-2010-2443
The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function.
- Libtiff
- ≤ 3.9.2, 3.4, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.8.0, 3.8.1, 3.8.2, 3.9, 3.9.0, 3.9.1
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 3.2% (87th percentile)
- NVD status
- Modified
- Published
- 2010-06-24
CVE-2010-2443 at NVD
1 known exploit for CVE-2010-2443
Proof-of-concept code and exploit modules indexed by Sploitus