Description
Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1632-1 | New tiff packages fix arbitrary code execution |
EUVD |
EUVD-2008-2323 | Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code. |
Ubuntu USN |
USN-639-1 | tiff vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T08:58:01.844Z
Reserved: 2008-05-18T00:00:00.000Z
Link: CVE-2008-2327
No data.
Status : Modified
Published: 2008-08-27T20:41:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-2327
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN