CVE-2010-2597 describes a denial-of-service vulnerability in LibTIFF versions 3.9.0 and 3.9.2, specifically within the TIFFVStripSize function in tif_strip.c. This flaw, triggered by incorrect TIFFGetField calls when processing crafted TIFF images (potentially related to downsampled OJPEG input or a compiler optimization leading to a divide-by-zero error), can cause an application crash. With a CVSS score of 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P), this vulnerability is remotely exploitable with medium attack complexity, leading to a partial availability impact. There is no evidence of active exploitation, no known exploit intelligence (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.9.0CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:3.9.0:*:*:*:*:*:*:* | ||
3.9.2CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:3.9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.