CVE-2006-2024
EPSS 14.9%tiff - several vulnerabilities
Published: 4/25/2006Modified: 4/28/2026
Also known as:DEBIAN-CVE-2006-2024
Description
Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.
Affected packages (2)
- Debian/tifffrom 0, < 3.8.1
- Debian/tifffrom 0, < 3.5.5-7woody1