The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.
References
Configurations
Information
Published : 2006-05-01 15:06
Updated : 2018-10-03 14:40
NVD link : CVE-2006-2120
Mitre link : CVE-2006-2120
JSON object : View
CWE
Products Affected
libtiff
- libtiff