CVE-2006-2656
Summary
| CVE | CVE-2006-2656 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-30 18:02:00 UTC |
| Updated | 2023-11-07 01:58:00 UTC |
| Description | Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Ubuntu update for tiff - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Debian update for tiff - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Gentoo update for tiff - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| [SECURITY] Fedora Core 4 Update: libtiff-3.7.1-6.fc4.2 |
FEDORA |
www.redhat.com |
Patch |
| USN-289-1: tiff vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| SUSE Updates for Multiple Packages - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Debian -- Security Information -- DSA-1091-1 tiff |
DEBIAN |
www.debian.org |
|
| SuSE Security announcements: [suse-security-announce] SUSE Security Summary Report SUSE-SR:2006:014 |
SUSE |
lists.suse.com |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| Gentoo Linux Documentation
--
libTIFF: Multiple buffer overflows |
GENTOO |
security.gentoo.org |
|
| 20060524 tiffsplit (libtiff <= 3.8.2) bss & stack buffer overflow... |
VULN-DEV |
marc.info |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2008-08-12 | Mark J Cox | This issue was addressed in libtiff packages as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 via: https://rhn.redhat.com/errata/RHSA-2006-0603.html Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. |
There are currently no legacy QID mappings associated with this CVE.