CVE-2010-2482
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.
- Libtiff
- ≤ 3.9.4, 3.4, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.8.0, 3.8.1, 3.8.2, 3.9.0, 3.9.1, 3.9.2, 3.9.3
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 8.8% (95th percentile)
- NVD status
- Modified
- Published
- 2010-07-06
CVE-2010-2482 at NVD
2 known exploits for CVE-2010-2482
Proof-of-concept code and exploit modules indexed by Sploitus