CVE-2006-3459
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 53%
from disclosure to weapon1322 days
Published on NVDAug 3
1st PoC+1322d
metasploitAug 1
exploitation probability
53%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.
Affected products
n/a · n/apublic PoCs found — 6
exploitdbwww.exploit-db.com/exploits/16862unverifiedexploitdbwww.exploit-db.com/exploits/16868unverifiedexploitdbwww.exploit-db.com/exploits/16869unverifiedexploitdbwww.exploit-db.com/exploits/21869unverifiedexploitdbwww.exploit-db.com/exploits/21868unverifiedexploitdbwww.exploit-db.com/exploits/11787unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-Pftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.aschttp://lists.apple.com/archives/security-announce/2006//Aug/msg00000.htmlhttp://lwn.net/Alerts/194228/http://secunia.com/advisories/21253http://secunia.com/advisories/21274http://secunia.com/advisories/21290http://secunia.com/advisories/21304http://secunia.com/advisories/21319http://secunia.com/advisories/21334http://secunia.com/advisories/21338http://secunia.com/advisories/21346