CVE-2008-2327

Impact:
Important
Public Date:
2008-08-26
Bugzilla:
458674: CVE-2008-2327 libtiff: use of uninitialized memory in LZW decoder

The MITRE CVE dictionary describes this issue as:

Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.

Find out more about CVE-2008-2327 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 3 (libtiff) RHSA-2008:0863 2008-08-28
Red Hat Enterprise Linux 5 (libtiff) RHSA-2008:0847 2008-08-28
Red Hat Enterprise Linux 4 (libtiff) RHSA-2008:0848 2008-08-28
Red Hat Enterprise Linux 2.1 (libtiff) RHSA-2008:0863 2008-08-28

Acknowledgements

Red Hat would like to thank Drew Yao of the Apple Product Security team for reporting this issue.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.