← All CVEs

CVE-2006-2025

medium · 6.5

Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.

6.5
CVSS
10.5%
EPSS (exploit prob.)
96th
EPSS percentile
2006-04-25
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

VendorProductAffected versions
libtifflibtiff<= 3.8.0
libtifflibtiff3.4
libtifflibtiff3.5.1
libtifflibtiff3.5.2
libtifflibtiff3.5.3
libtifflibtiff3.5.4
libtifflibtiff3.5.5
libtifflibtiff3.5.6
libtifflibtiff3.5.7
libtifflibtiff3.6.0
libtifflibtiff3.6.1
libtifflibtiff3.7.0
libtifflibtiff3.7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-2025