CVE-2006-2193

critical

Description

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

References

https://usn.ubuntu.com/289-1/

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9788

https://exchange.xforce.ibmcloud.com/vulnerabilities/26991

http://www.vupen.com/english/advisories/2007/4034

http://www.vupen.com/english/advisories/2007/3486

http://www.vupen.com/english/advisories/2006/2197

http://www.securityfocus.com/bid/18331

http://www.redhat.com/support/errata/RHSA-2008-0848.html

http://www.mandriva.com/security/advisories?name=MDKSA-2006:102

http://www.debian.org/security/2006/dsa-1091

http://sunsolve.sun.com/search/document.do?assetkey=1-66-201331-1

http://sunsolve.sun.com/search/document.do?assetkey=1-26-103160-1

http://security.gentoo.org/glsa/glsa-200607-03.xml

http://secunia.com/advisories/31670

http://secunia.com/advisories/27832

http://secunia.com/advisories/27222

http://secunia.com/advisories/27181

http://secunia.com/advisories/21002

http://secunia.com/advisories/20766

http://secunia.com/advisories/20693

http://secunia.com/advisories/20520

http://secunia.com/advisories/20501

http://secunia.com/advisories/20488

http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=370355

Details

Source: Mitre, NVD

Published: 2006-06-08

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical