Unrated severityNVD Advisory· Published Jul 14, 2009· Updated Jun 16, 2026
CVE-2009-2347
CVE-2009-2347
Description
Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7>=3.8, <=3.8.2, =3.9, =4.0+ 5 more
- (no CPE)range: >=3.8, <=3.8.2, =3.9, =4.0
- cpe:2.3:a:libtiff:libtiff:3.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:3.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:3.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:3.9:*:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
29- article.gmane.org/gmane.linux.debian.devel.changes.unstable/178563/nvdPatch
- bugzilla.maptools.org/show_bug.cginvdPatch
- www.mandriva.com/security/advisoriesnvdPatch
- www.ocert.org/advisories/ocert-2009-012.htmlnvdPatch
- www.securityfocus.com/bid/35652nvdPatch
- www.vupen.com/english/advisories/2009/1870nvdPatchVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdPatch
- secunia.com/advisories/35817nvdVendor Advisory
- osvdb.org/55821nvd
- osvdb.org/55822nvd
- secunia.com/advisories/35811nvd
- secunia.com/advisories/35866nvd
- secunia.com/advisories/35883nvd
- secunia.com/advisories/35911nvd
- secunia.com/advisories/36194nvd
- secunia.com/advisories/50726nvd
- security.gentoo.org/glsa/glsa-200908-03.xmlnvd
- security.gentoo.org/glsa/glsa-201209-02.xmlnvd
- www.debian.org/security/2009/dsa-1835nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2009-1159.htmlnvd
- www.securityfocus.com/archive/1/504892/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-801-1nvd
- www.vupen.com/english/advisories/2011/0621nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/51688nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10988nvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00663.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00724.htmlnvd
News mentions
0No linked articles in our index yet.