CVE-2006-3463

CVE-2006-3463

CVE-2006-3463 · HIGH Severity

AV:N/AC:L/AU:N/C:N/I:N/A:C

The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, which allows context-dependent attackers to cause a denial of service via a large td_nstrips value, which triggers an infinite loop.

Learn more about our Web Application Penetration Testing UK.