CVE-2006-2026

Publication date 25 April 2006

Last updated 17 July 2025


Ubuntu priority

Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."

Status

Package Ubuntu Release Status
tiff 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 3.7.4-1ubuntu3.2

References

Related Ubuntu Security Notices (USN)

    • USN-277-1
    • TIFF library vulnerabilities
    • 4 May 2006

Other references