CVE-2010-2630
LibTIFF 3.9.4 - Out-Of-Order Tag Type Mismatch Remote Denial of Service
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
La función TIFFReadDirectory en LibTIFF v3.9.0 no valida adecuadamente los tipos de datos de etiquetas codec-specific que tiene una posición fuera de orden en los ficheros TIFF, lo que permite a atacantes remotos causar una denegación de servicio (caída programa) a través de ficheros manipulados, una vulnerabilidad diferente que CVE-2010-2481.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-07-06 CVE Reserved
- 2010-07-06 CVE Published
- 2010-07-12 First Exploit
- 2023-12-02 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/50726 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/34278 | 2010-07-12 |
URL | Date | SRC |
---|---|---|
http://bugzilla.maptools.org/show_bug.cgi?id=2210 | 2013-05-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=554371 | 2013-05-15 |
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-201209-02.xml | 2013-05-15 | |
http://www.debian.org/security/2012/dsa-2552 | 2013-05-15 |