4.3
CVE-2010-2598
- EPSS 1.99%
- Veröffentlicht 02.07.2010 12:43:53
- Zuletzt bearbeitet 16.06.2026 23:21:03
- Erkennungen
LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to cause a denial of service via a crafted TIFF image, related to "downsampled OJPEG input."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 3
Redhat ≫ Enterprise Linux Version 3 Update ga
Redhat ≫ Enterprise Linux Version 3 Update ga Edition as
Redhat ≫ Enterprise Linux Version 3 Update ga Edition desktop
Redhat ≫ Enterprise Linux Version 3 Update ga Edition es
Redhat ≫ Enterprise Linux Version 3 Update ga Edition ws
Redhat ≫ Enterprise Linux Version 3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.99% | 0.78 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/40536
http://www.redhat.com/support/errata/RHSA-2010-0520.html
http://www.vupen.com/english/advisories/2010/1761
https://bugzilla.redhat.com/show_bug.cgi?id=583081