← Vulnerability feed

Vulnerability record · CVE-2006-3459 · published 3 August 2006

CVE-2006-3459: libtiff TIFFFetchShortPair stack buffer overflow via crafted TIFF

Libtiff · Libtiff

libtiff before 3.8.2 contains multiple stack-based buffer overflows, including one reachable through a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c. Because libtiff is embedded in many image-handling products, including Adobe Reader 9.3.0, a malformed TIFF can crash or compromise any application that parses it.

7.5 CVSS 2.0 High EPSS 54% · top 1.0% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
94References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a high EPSS score, though no confirmed in-the-wild exploitation is recorded.

What it is

libtiff before 3.8.2 contains multiple stack-based buffer overflows, including one reachable through a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c. Because libtiff is embedded in many image-handling products, including Adobe Reader 9.3.0, a malformed TIFF can crash or compromise any application that parses it.

Impact

An attacker can execute arbitrary code in the context of the process that parses the TIFF, or cause a denial of service through a crash.

Attack surface

Reached by supplying a crafted TIFF file to a vulnerable libtiff-based parser; the CVSS vector AV:N/AC:L/Au:N indicates network delivery with no authentication, and exploitation typically requires the victim to open or process the file.

Exploitation

Not listed in CISA KEV, but EPSS is 0.5368 (99th percentile), indicating high predicted exploitation activity; references are vendor advisories without exploit tags.

What to do

  • Upgrade libtiff to 3.8.2 or later, and apply the corresponding vendor patches for products bundling libtiff such as Adobe Reader.
  • Inventory applications and libraries that embed libtiff and confirm their bundled version.
  • Block or sandbox untrusted TIFF processing, and disable automatic image preview or thumbnail generation where feasible.
  • Apply vendor advisories listed in the references for OS and application packages that ship libtiff.

Detection

  • Monitor for crashes or abnormal process termination in applications that parse TIFF files.
  • Scan for TIFF files with unusually large tdir_count or malformed directory entries in mail attachments and file uploads.
  • Track libtiff versions across endpoints and flag hosts running versions before 3.8.2.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
http://lwn.net/Alerts/194228/
http://secunia.com/advisories/21253 Vendor Advisory
http://secunia.com/advisories/21274 Vendor Advisory
http://secunia.com/advisories/21290
http://secunia.com/advisories/21304 Vendor Advisory
http://secunia.com/advisories/21319 Vendor Advisory
http://secunia.com/advisories/21334 Vendor Advisory
http://secunia.com/advisories/21338 Vendor Advisory
http://secunia.com/advisories/21346 Vendor Advisory
http://secunia.com/advisories/21370 Vendor Advisory
http://secunia.com/advisories/21392 Vendor Advisory
http://secunia.com/advisories/21501 Vendor Advisory
http://secunia.com/advisories/21537 Vendor Advisory
http://secunia.com/advisories/21598 Vendor Advisory
http://secunia.com/advisories/21632 Vendor Advisory
http://secunia.com/advisories/22036 Vendor Advisory
http://secunia.com/advisories/27181 Vendor Advisory
http://secunia.com/advisories/27222 Vendor Advisory
http://secunia.com/advisories/27832 Vendor Advisory
http://secunia.com/blog/76 Vendor Advisory
http://securitytracker.com/id?1016628
http://securitytracker.com/id?1016671
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.536600
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103160-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201331-1
http://support.avaya.com/elmodocs2/security/ASA-2006-166.htm
http://www.debian.org/security/2006/dsa-1137 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200608-07.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:136
http://www.mandriva.com/security/advisories?name=MDKSA-2006:137
http://www.novell.com/linux/security/advisories/2006_44_libtiff.html
http://www.osvdb.org/27723
http://www.redhat.com/support/errata/RHSA-2006-0603.html
http://www.redhat.com/support/errata/RHSA-2006-0648.html
http://www.securityfocus.com/bid/19283
http://www.securityfocus.com/bid/19289
http://www.ubuntu.com/usn/usn-330-1

Track CVE-2006-3459 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0929Libtiff vulnerabilityHeap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPE…EPSS 8.2%10.0CVE-2004-1308Libtiff vulnerabilityInteger overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF fil…EPSS 15%9.8CVE-2016-9540Libtiff memory buffer overflow vulnerabilitytools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStr…EPSS 3.6%9.8CVE-2016-9539Libtiff memory buffer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.EPSS 3.0%9.8CVE-2016-9538Libtiff integer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35…EPSS 3.4%9.8CVE-2016-9537Libtiff memory buffer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.EPSS 3.1%9.8CVE-2016-9536Libtiff memory buffer overflow vulnerabilitytools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 350…EPSS 3.1%9.8CVE-2016-9535Libtiff memory buffer overflow vulnerabilitytif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mo…EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-2006-3459), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.