Sploitus

CVE-2010-2482

2 known exploits for CVE-2010-2482

LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.

Affected products
Libtiff, Tiff
Libtiff
≤ 3.9.4, 3.4, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.8.0, 3.8.1, 3.8.2, 3.9.0, 3.9.1, 3.9.2, 3.9.3
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
8.8% (95th percentile)
NVD status
Modified
Published
2010-07-06
CVE-2010-2482 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2010-2482

Proof-of-concept code and exploit modules indexed by Sploitus