PublicDate: 2006-04-25 23:02:00 UTC Candidate: CVE-2006-2026 References: https://ubuntu.com/security/notices/USN-277-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2026 Description: Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions." Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_tiff: released (3.7.4-1ubuntu3.2) edgy_tiff: not-affected feisty_tiff: not-affected upstream_tiff: needs-triage