VYPR
Unrated severityNVD Advisory· Published Apr 25, 2006· Updated Apr 16, 2026

CVE-2006-2026

CVE-2006-2026

Description

Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."

Affected products

13
  • LibTIFF/Libtiff13 versions
    cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:*+ 12 more
    • cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:3.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*range: <=3.8.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

27

News mentions

0

No linked articles in our index yet.