Description
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2084-1 | New tiff packages fix arbitrary code execution |
EUVD |
EUVD-2010-1439 | Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow. |
Ubuntu USN |
USN-954-1 | tiff vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-07T01:21:19.175Z
Reserved: 2010-04-15T00:00:00.000Z
Link: CVE-2010-1411
No data.
Status : Modified
Published: 2010-06-17T16:30:01.810
Modified: 2026-04-29T01:13:23.040
Link: CVE-2010-1411
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN