CVE-2006-2193
CVE-2006-2193
Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=370355http://bugzilla.remotesensing.org/show_bug.cgi?id=1196http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.htmlhttp://secunia.com/advisories/20488http://secunia.com/advisories/20501http://secunia.com/advisories/20520http://secunia.com/advisories/20693http://secunia.com/advisories/20766http://secunia.com/advisories/21002http://secunia.com/advisories/27181http://secunia.com/advisories/27222http://secunia.com/advisories/27832