The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, which allows context-dependent attackers to cause a denial of service via a large td_nstrips value, which triggers an infinite loop.
References
Configurations
Information
Published : 2006-08-02 18:04
Updated : 2017-10-10 18:31
NVD link : CVE-2006-3463
Mitre link : CVE-2006-3463
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
libtiff
- libtiff