CVE-2009-3296 describes multiple integer overflows in tiffread.c within CamlImages 2.2, potentially allowing remote attackers to execute arbitrary code through specially crafted TIFF images with large width and height values, leading to heap-based buffer overflows. This vulnerability carries a CVSS score of 7.5, indicating high severity, with a network-based attack vector requiring low complexity and no authentication, potentially leading to partial confidentiality, integrity, and availability compromise. There is no evidence of active exploitation, no publicly available exploit code in Metasploit or ExploitDB, and minimal community discussion or media coverage, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2CPE matchmatch criteria | cpe:2.3:a:gallium.inria:camimages:2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.