CVE-2010-2598
Published Jul 2, 2010
Last updated 8 years ago
Overview
- Description
- LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to cause a denial of service via a crafted TIFF image, related to "downsampled OJPEG input."
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "444EBE64-D3C8-41E9-8E02-22C6BDA2876B" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3:ga:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CBD33CE-B3AE-44C6-9E0F-1AA0E72FD609" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3:ga:as:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFDF9897-AE74-4EEA-990A-EF029A317254" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3:ga:desktop:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C98BB168-05EA-4801-95D6-7A4D14F3A309" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3:ga:es:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5AF0549C-3415-4A3E-8D4D-54439FDA73E2" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3:ga:ws:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56DDBFEB-72F7-478A-BEA2-80BBEC242B9C" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40D8DAE0-8E75-435C-9BD6-FAEED2ACB47C" } ], "operator": "OR" } ] } ]