CVE-2006-2026

Publication date 25 April 2006

Last updated 24 July 2024


Ubuntu priority

Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to “setfield/getfield methods in cleanup functions.”

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
tiff 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 3.7.4-1ubuntu3.2

References

Related Ubuntu Security Notices (USN)

    • USN-277-1
    • TIFF library vulnerabilities
    • 4 May 2006

Other references