Unrated severityNVD Advisory· Published Jul 1, 2009· Updated Apr 23, 2026
CVE-2009-2285
CVE-2009-2285
Description
Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
41- bugzilla.maptools.org/show_bug.cginvdExploit
- www.lan.st/showthread.phpnvdExploit
- www.openwall.com/lists/oss-security/2009/06/22/1nvdExploit
- www.openwall.com/lists/oss-security/2009/06/29/5nvdExploit
- bugs.launchpad.net/ubuntu/+source/tiff/+bug/380149nvdExploit
- lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlnvd
- lists.apple.com/archives/security-announce/2010//Mar/msg00003.htmlnvd
- lists.apple.com/archives/security-announce/2010/Feb/msg00000.htmlnvd
- lists.apple.com/archives/security-announce/2010/Jan/msg00000.htmlnvd
- lists.apple.com/archives/security-announce/2010/Mar/msg00000.htmlnvd
- secunia.com/advisories/35695nvd
- secunia.com/advisories/35716nvd
- secunia.com/advisories/35866nvd
- secunia.com/advisories/35883nvd
- secunia.com/advisories/35912nvd
- secunia.com/advisories/36194nvd
- secunia.com/advisories/36831nvd
- secunia.com/advisories/38241nvd
- secunia.com/advisories/39135nvd
- security.gentoo.org/glsa/glsa-200908-03.xmlnvd
- sunsolve.sun.com/search/document.donvd
- support.apple.com/kb/HT3937nvd
- support.apple.com/kb/HT4004nvd
- support.apple.com/kb/HT4013nvd
- support.apple.com/kb/HT4070nvd
- support.apple.com/kb/HT4105nvd
- www.debian.org/security/2009/dsa-1835nvd
- www.openwall.com/lists/oss-security/2009/06/23/1nvd
- www.redhat.com/support/errata/RHSA-2009-1159.htmlnvd
- www.vupen.com/english/advisories/2009/1637nvd
- www.vupen.com/english/advisories/2009/2727nvd
- www.vupen.com/english/advisories/2009/3184nvd
- www.vupen.com/english/advisories/2010/0173nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10145nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7049nvd
- usn.ubuntu.com/797-1/nvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00142.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00161.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00230.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00655.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00714.htmlnvd
News mentions
0No linked articles in our index yet.