This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Name CVE-2009-3296 First vendor Publication 2009-10-20
Vendor Cve Last vendor Modification 2009-10-21

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3296

% Id Name
100 % CWE-189 Numeric Errors (CWE/SANS Top 25)

Application 1

Date Description
2011-03-09 Name : Gentoo Security Advisory GLSA 201006-02 (camlimages)
File : nvt/glsa_201006_02.nasl
2009-11-17 Name : Fedora Core 10 FEDORA-2009-10568 (ocaml-camlimages)
File : nvt/fcore_2009_10568.nasl
2009-11-17 Name : Fedora Core 11 FEDORA-2009-10594 (ocaml-camlimages)
File : nvt/fcore_2009_10594.nasl
2009-10-27 Name : Debian Security Advisory DSA 1912-2 (advi)
File : nvt/deb_1912_2.nasl
2009-10-27 Name : Mandrake Security Advisory MDVSA-2009:286 (ocaml-camlimages)
File : nvt/mdksa_2009_286.nasl
2009-10-19 Name : Debian Security Advisory DSA 1912-1 (camlimages)
File : nvt/deb_1912_1.nasl

Id Description
59083 CamlImages tiffread.c TIFF File Handling Multiple Overflows

Date Description
2010-06-02 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201006-02.nasl - Type : ACT_GATHER_INFO
2010-02-24 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1912.nasl - Type : ACT_GATHER_INFO
2009-11-11 Name : The remote Fedora host is missing a security update.
File : fedora_2009-10568.nasl - Type : ACT_GATHER_INFO
2009-11-11 Name : The remote Fedora host is missing a security update.
File : fedora_2009-10594.nasl - Type : ACT_GATHER_INFO

Source Url
BID http://www.securityfocus.com/bid/36713
CONFIRM http://security.debian.org/pool/updates/main/c/camlimages/camlimages_2.2.0-4+...
DEBIAN http://www.debian.org/security/2009/dsa-1912
SECUNIA http://secunia.com/advisories/37067

