CVE-2010-2630
Publication date 6 July 2010
Last updated 24 July 2024
Ubuntu priority
Description
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| tiff | 10.10 maverick | 
                              
                               
                                Fixed 3.9.4-2ubuntu0.1 
                                
                               
                             |      
                          
                            
                          
                        
                      
| 10.04 LTS lucid | 
                              
                               
                                Fixed 3.9.2-2ubuntu0.4 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 9.10 karmic | 
                              
                               
                                Fixed 3.8.2-13ubuntu0.4 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 9.04 jaunty | Ignored end of life | |
| 8.04 LTS hardy | 
                              
                               
                                Fixed 3.8.2-7ubuntu3.7 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 6.06 LTS dapper | 
                              
                               
                                Fixed 3.7.4-1ubuntu3.9 
                                
                               
                             |      
                          
                            
                          
                        
                      
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1085-1
 - tiff vulnerabilities
 - 7 March 2011