Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via…

cve CVE-2006-2656 3 sources, 3 claims · Watch

NVD writes:
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE. the claim
EPSS
0.14415 EPSS
Vendor
n/a NVD
Product
n/a NVD
CWE
CWE-119 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept · Exploit-DB 2006-05-26
  3. Proof of concept, verified · Exploit-DB 2006-05-26
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2006-05-26first spoke of it: tiffsplit (libtiff 3.8.2) - Local Stack Buffer OverflowExploit-DB
2006-05-30first spoke of it: Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.NVD
2026-10-05first spoke of it: CVE-2006-2656EPSS

Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.

What it is to other things

affectslibtiff/libtiff
NVD
made_bylibtiff
NVD

In words only, so not counted until a person confirms one:

made_byn_a
NVD says “n/a”
affectsn_a/n_a
NVD says “n/a · n/a”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Author
author
Exploit-DBnitr0us
receipt
Source
Exploit-DB
Its words
nitr0us
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-06 12:11 UTC
Original
open at the source
What the source handed over
{
  "aliases": "05262006-tiffspl33t.tar.gz",
  "application_url": "http://www.exploit-db.comtiff-3.8.2.tar.gz",
  "author": "nitr0us",
  "codes": "OSVDB-26030;CVE-2006-2656",
  "date_added": "2006-05-25",
  "date_published": "2006-05-26",
  "date_updated": "2016-07-29",
  "description": "tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow",
  "file": "exploits/linux/local/1831.txt",
  "id": "1831",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "1"
}
—
CWE
cwe
NVDCWE-119
receipt
Source
NVD
Its words
CWE-119
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCWE-119
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "36B8B853-0FF0-4E2F-983D-683A0951CEF3",
                "versionEndIncluding": "3.8.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "CCA5EEB8-9D2C-49A9-BB08-CE5017B79D81",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "261FAE51-5207-4136-9FFE-2330A281266C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.2:*:*:*:*:*:*:*",
                "matchCriteriaId": "B32C83B9-F7DA-450A-A687-9A73734CD712",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.3:*:*:*:*:*:*:*",
                "matchCriteriaId": "9485283A-B73E-4567-914A-42A86F5FFCB4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "95892168-0FB6-4E3F-9303-2F9B3CF60D2B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.5:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5021564-5E0A-4DDC-BC68-200B6050043E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.6:*:*:*:*:*:*:*",
                "matchCriteriaId": "11C50750-FE1D-42BA-9125-7D8E872AA2DB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "19AA66E5-FDDD-4243-B945-DFEBDD25F258",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "62F359CD-5DC4-4919-B8E1-95BDDBD27EFC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "D2C8C550-3313-4266-B4B3-E9E9047CFE04",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "ABEEBA7B-81D5-4148-912B-9AD448BBE741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "448555FE-8E91-4EA7-BA05-6915F5508319",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "44BC5E2C-B6A6-4999-A1EA-B91DA5C350C7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "F2850FD9-8BE8-410E-8A24-28549DAACEB3",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename.  NOTE: tiffsplit is not setuid.  If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE."
      },
      {
        "lang": "es",
        "value": "Desbordamiento de búfer basado en pila en el comando tiffsplit en libtiff 3.8.2 y versiones anteriores podría permitir a atacantes ejecutar código arbitrario a través de un nombre de archivo largo. NOTA: tiffsplit no es setuid. Si no hay un escenario común bajo el cual tiffsplit es llamado con argumentos de línea de comando controlados por el atacante, entonces quizá este problema no debería ser incluido en una CVE."
      }
    ],
    "id": "CVE-2006-2656",
    "lastModified": "2026-09-23T13:10:00.153",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 7.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 10.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": true,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ]
    },
    "published": "2006-05-30T18:02:00.000",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vendorComments": [
      {
        "comment": "This issue was addressed in libtiff packages as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 via: https://rhn.redhat.com/errata/RHSA-2006-0603.html\n\nRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.",
        "lastModified": "2008-08-12T00:00:00",
        "organization": "Red Hat"
      }
    ],
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
EPSS
epss
EPSS0.14415
receipt
Source
EPSS
Its words
0.144150000
Read by
field:epss
Said since
2026-10-06 12:18 UTC
Last answered
2026-10-06 12:19 UTC
Original
open at the source
What the source handed over
{
  "cve": "CVE-2006-2656",
  "date": "2026-10-05",
  "epss": "0.144150000",
  "percentile": "0.965290000"
}
—
EPSS percentile
epss_percentile
EPSS0.96529
receipt
Source
EPSS
Its words
0.965290000
Read by
field:percentile
Said since
2026-10-06 12:18 UTC
Last answered
2026-10-06 12:19 UTC
Original
open at the source
What the source handed over
{
  "cve": "CVE-2006-2656",
  "date": "2026-10-05",
  "epss": "0.144150000",
  "percentile": "0.965290000"
}
—
Platform
platform
Exploit-DBlinux
receipt
Source
Exploit-DB
Its words
linux
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-06 12:11 UTC
Original
open at the source
What the source handed over
{
  "aliases": "05262006-tiffspl33t.tar.gz",
  "application_url": "http://www.exploit-db.comtiff-3.8.2.tar.gz",
  "author": "nitr0us",
  "codes": "OSVDB-26030;CVE-2006-2656",
  "date_added": "2006-05-25",
  "date_published": "2006-05-26",
  "date_updated": "2016-07-29",
  "description": "tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow",
  "file": "exploits/linux/local/1831.txt",
  "id": "1831",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "1"
}
—
Product
product
NVDn/a
receipt
Source
NVD
Its words
n/a
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCn/a
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "36B8B853-0FF0-4E2F-983D-683A0951CEF3",
                "versionEndIncluding": "3.8.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "CCA5EEB8-9D2C-49A9-BB08-CE5017B79D81",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "261FAE51-5207-4136-9FFE-2330A281266C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.2:*:*:*:*:*:*:*",
                "matchCriteriaId": "B32C83B9-F7DA-450A-A687-9A73734CD712",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.3:*:*:*:*:*:*:*",
                "matchCriteriaId": "9485283A-B73E-4567-914A-42A86F5FFCB4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "95892168-0FB6-4E3F-9303-2F9B3CF60D2B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.5:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5021564-5E0A-4DDC-BC68-200B6050043E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.6:*:*:*:*:*:*:*",
                "matchCriteriaId": "11C50750-FE1D-42BA-9125-7D8E872AA2DB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "19AA66E5-FDDD-4243-B945-DFEBDD25F258",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "62F359CD-5DC4-4919-B8E1-95BDDBD27EFC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "D2C8C550-3313-4266-B4B3-E9E9047CFE04",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "ABEEBA7B-81D5-4148-912B-9AD448BBE741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "448555FE-8E91-4EA7-BA05-6915F5508319",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "44BC5E2C-B6A6-4999-A1EA-B91DA5C350C7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "F2850FD9-8BE8-410E-8A24-28549DAACEB3",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename.  NOTE: tiffsplit is not setuid.  If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE."
      },
      {
        "lang": "es",
        "value": "Desbordamiento de búfer basado en pila en el comando tiffsplit en libtiff 3.8.2 y versiones anteriores podría permitir a atacantes ejecutar código arbitrario a través de un nombre de archivo largo. NOTA: tiffsplit no es setuid. Si no hay un escenario común bajo el cual tiffsplit es llamado con argumentos de línea de comando controlados por el atacante, entonces quizá este problema no debería ser incluido en una CVE."
      }
    ],
    "id": "CVE-2006-2656",
    "lastModified": "2026-09-23T13:10:00.153",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 7.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 10.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": true,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ]
    },
    "published": "2006-05-30T18:02:00.000",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vendorComments": [
      {
        "comment": "This issue was addressed in libtiff packages as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 via: https://rhn.redhat.com/errata/RHSA-2006-0603.html\n\nRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.",
        "lastModified": "2008-08-12T00:00:00",
        "organization": "Red Hat"
      }
    ],
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "36B8B853-0FF0-4E2F-983D-683A0951CEF3",
                "versionEndIncluding": "3.8.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "CCA5EEB8-9D2C-49A9-BB08-CE5017B79D81",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "261FAE51-5207-4136-9FFE-2330A281266C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.2:*:*:*:*:*:*:*",
                "matchCriteriaId": "B32C83B9-F7DA-450A-A687-9A73734CD712",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.3:*:*:*:*:*:*:*",
                "matchCriteriaId": "9485283A-B73E-4567-914A-42A86F5FFCB4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "95892168-0FB6-4E3F-9303-2F9B3CF60D2B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.5:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5021564-5E0A-4DDC-BC68-200B6050043E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.6:*:*:*:*:*:*:*",
                "matchCriteriaId": "11C50750-FE1D-42BA-9125-7D8E872AA2DB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "19AA66E5-FDDD-4243-B945-DFEBDD25F258",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "62F359CD-5DC4-4919-B8E1-95BDDBD27EFC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "D2C8C550-3313-4266-B4B3-E9E9047CFE04",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "ABEEBA7B-81D5-4148-912B-9AD448BBE741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "448555FE-8E91-4EA7-BA05-6915F5508319",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "44BC5E2C-B6A6-4999-A1EA-B91DA5C350C7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "F2850FD9-8BE8-410E-8A24-28549DAACEB3",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename.  NOTE: tiffsplit is not setuid.  If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE."
      },
      {
        "lang": "es",
        "value": "Desbordamiento de búfer basado en pila en el comando tiffsplit en libtiff 3.8.2 y versiones anteriores podría permitir a atacantes ejecutar código arbitrario a través de un nombre de archivo largo. NOTA: tiffsplit no es setuid. Si no hay un escenario común bajo el cual tiffsplit es llamado con argumentos de línea de comando controlados por el atacante, entonces quizá este problema no debería ser incluido en una CVE."
      }
    ],
    "id": "CVE-2006-2656",
    "lastModified": "2026-09-23T13:10:00.153",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 7.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 10.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": true,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ]
    },
    "published": "2006-05-30T18:02:00.000",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vendorComments": [
      {
        "comment": "This issue was addressed in libtiff packages as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 via: https://rhn.redhat.com/errata/RHSA-2006-0603.html\n\nRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.",
        "lastModified": "2008-08-12T00:00:00",
        "organization": "Red Hat"
      }
    ],
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Type
type
Exploit-DBlocal
receipt
Source
Exploit-DB
Its words
local
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-06 12:11 UTC
Original
open at the source
What the source handed over
{
  "aliases": "05262006-tiffspl33t.tar.gz",
  "application_url": "http://www.exploit-db.comtiff-3.8.2.tar.gz",
  "author": "nitr0us",
  "codes": "OSVDB-26030;CVE-2006-2656",
  "date_added": "2006-05-25",
  "date_published": "2006-05-26",
  "date_updated": "2016-07-29",
  "description": "tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow",
  "file": "exploits/linux/local/1831.txt",
  "id": "1831",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "1"
}
—
Vendor
vendor
NVDn/a
receipt
Source
NVD
Its words
n/a
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCn/a
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "36B8B853-0FF0-4E2F-983D-683A0951CEF3",
                "versionEndIncluding": "3.8.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "CCA5EEB8-9D2C-49A9-BB08-CE5017B79D81",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "261FAE51-5207-4136-9FFE-2330A281266C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.2:*:*:*:*:*:*:*",
                "matchCriteriaId": "B32C83B9-F7DA-450A-A687-9A73734CD712",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.3:*:*:*:*:*:*:*",
                "matchCriteriaId": "9485283A-B73E-4567-914A-42A86F5FFCB4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.4:*:*:*:*:*:*:*",
                "matchCriteriaId": "95892168-0FB6-4E3F-9303-2F9B3CF60D2B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.5:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5021564-5E0A-4DDC-BC68-200B6050043E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.6:*:*:*:*:*:*:*",
                "matchCriteriaId": "11C50750-FE1D-42BA-9125-7D8E872AA2DB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.5.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "19AA66E5-FDDD-4243-B945-DFEBDD25F258",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "62F359CD-5DC4-4919-B8E1-95BDDBD27EFC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.6.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "D2C8C550-3313-4266-B4B3-E9E9047CFE04",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "ABEEBA7B-81D5-4148-912B-9AD448BBE741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.7.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "448555FE-8E91-4EA7-BA05-6915F5508319",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "44BC5E2C-B6A6-4999-A1EA-B91DA5C350C7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:libtiff:libtiff:3.8.1:*:*:*:*:*:*:*",
                "matchCriteriaId": "F2850FD9-8BE8-410E-8A24-28549DAACEB3",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename.  NOTE: tiffsplit is not setuid.  If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE."
      },
      {
        "lang": "es",
        "value": "Desbordamiento de búfer basado en pila en el comando tiffsplit en libtiff 3.8.2 y versiones anteriores podría permitir a atacantes ejecutar código arbitrario a través de un nombre de archivo largo. NOTA: tiffsplit no es setuid. Si no hay un escenario común bajo el cual tiffsplit es llamado con argumentos de línea de comando controlados por el atacante, entonces quizá este problema no debería ser incluido en una CVE."
      }
    ],
    "id": "CVE-2006-2656",
    "lastModified": "2026-09-23T13:10:00.153",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 7.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 10.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": true,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ]
    },
    "published": "2006-05-30T18:02:00.000",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "secalert@redhat.com",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://marc.info/?l=vuln-dev&m=114857412916909&w=2"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20501"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20520"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/20766"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "http://secunia.com/advisories/21002"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://security.gentoo.org/glsa/glsa-200607-03.xml"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.debian.org/security/2006/dsa-1091"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:095"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://usn.ubuntu.com/289-1/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch"
        ],
        "url": "https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00127.html"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vendorComments": [
      {
        "comment": "This issue was addressed in libtiff packages as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 via: https://rhn.redhat.com/errata/RHSA-2006-0603.html\n\nRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.",
        "lastModified": "2008-08-12T00:00:00",
        "organization": "Red Hat"
      }
    ],
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Verified
verified
Exploit-DBtrue
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-06 12:11 UTC
Original
open at the source
What the source handed over
{
  "aliases": "05262006-tiffspl33t.tar.gz",
  "application_url": "http://www.exploit-db.comtiff-3.8.2.tar.gz",
  "author": "nitr0us",
  "codes": "OSVDB-26030;CVE-2006-2656",
  "date_added": "2006-05-25",
  "date_published": "2006-05-26",
  "date_updated": "2016-07-29",
  "description": "tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow",
  "file": "exploits/linux/local/1831.txt",
  "id": "1831",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "1"
}
—
Every claim, by kind

vulnerability

Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.
zetlyn/cve-nvd · 2006-05-30
cwe CWE-119 product n/a status Modified vendor n/a source
CVE-2006-2656
zetlyn/cve-epss · 2026-10-05
epss 0.14415 epss_percentile 0.96529 source

exploit

tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow
zetlyn/cve-exploitdb · 2006-05-26
author nitr0us platform linux type local verified true source