CVE-2006-2656

Source
https://cve.org/CVERecord?id=CVE-2006-2656
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2006-2656.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2006-2656
Downstream
Related
Withdrawn
2026-01-27T04:07:21.555315Z
Published
2006-05-30T18:02:00Z
Modified
2026-01-27T04:07:21.555315Z
Summary
[none]
Details

Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.

References

Affected packages