4.3

CVE-2010-2598

Exploit
LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to cause a denial of service via a crafted TIFF image, related to "downsampled OJPEG input."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 3
Redhat ≫ Enterprise Linux Version 3 Update ga
Redhat ≫ Enterprise Linux Version 3 Update ga Edition as
Redhat ≫ Enterprise Linux Version 3 Update ga Edition desktop
Redhat ≫ Enterprise Linux Version 3 Update ga Edition es
Redhat ≫ Enterprise Linux Version 3 Update ga Edition ws
Redhat ≫ Enterprise Linux Version 3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.99% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/40536
Third Party Advisory
Permissions Required
http://www.redhat.com/support/errata/RHSA-2010-0520.html
Not Applicable
http://www.vupen.com/english/advisories/2010/1761
Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=583081
Exploit