The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, which allows context-dependent attackers to cause a denial of service via a large td_nstrips value, which triggers an infinite loop.
References
Configurations
History
No history.
Information
Published : 2006-08-03 01:04
Updated : 2024-02-04 16:52
NVD link : CVE-2006-3463
Mitre link : CVE-2006-3463
CVE.ORG link : CVE-2006-3463
JSON object : View
Products Affected
libtiff
- libtiff
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer