Sun Security Blog
|
20 Aug 2009
Sun Alert 265808 Multiple Integer Overflow Vulnerabilities in the libtiff(3) Image Conversion Tools 'tiff2rgba' and 'rgb2ycbcr' May Lead to Arbitrary Code Execution
Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris Multiple integer overflow vulnerabilities in the libtiff(3) image conversion tools 'tiff2rgba' and 'rgb2ycbcr' may allow a local or remote unprivileged user to execute arbitrary code via a TIFF image with large width and height values. This issue is also described in the following document: CVE-2009-2347 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347 State: Workaround First released: 14-Aug-2009
Permalink
|
Comments:
Post a Comment: Comments are closed for this entry. |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||