LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.
http://bugzilla.maptools.org/show_bug.cgi?id=1996
http://marc.info/?l=oss-security&m=127736307002102&w=2
http://marc.info/?l=oss-security&m=127738540902757&w=2
http://marc.info/?l=oss-security&m=127797353202873&w=2
http://secunia.com/advisories/40422
http://secunia.com/advisories/50726
http://security.gentoo.org/glsa/glsa-201209-02.xml
http://www.debian.org/security/2012/dsa-2552
http://www.openwall.com/lists/oss-security/2010/06/30/22
https://bugs.launchpad.net/bugs/597246
Source: MITRE
Published: 2010-07-06
Updated: 2013-05-15
Type: NVD-CWE-Other
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM