Description
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1091-1 | New TIFF packages fix arbitrary code execution |
Ubuntu USN |
USN-289-1 | tiff vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T17:58:51.709Z
Reserved: 2006-05-30T00:00:00.000Z
Link: CVE-2006-2656
No data.
Status : Modified
Published: 2006-05-30T18:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-2656
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN