Security Advisory

CVE-2006-3463

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-08-03 01:00:00
Last updated 2024-08-07 18:30:33
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, which allows context-dependent attackers to cause a denial of service via a large td_nstrips value, which triggers an infinite loop.