Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2010-2067 at MITRE


Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long EXIF SubjectDistance field in a TIFF file.

NVD CVSS v2 Base Score: 6.82 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

SUSE information

SUSE Bugzilla entries: 612787 [RESOLVED / FIXED], 612879 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.3
  • tiff-debuginfo >= 3.9.2-5.1.1
  • tiff-debugsource >= 3.9.2-5.1.1
openSUSE 11.3
  • tiff >= 3.9.2-5.1.1