Libtiff · Libtiff · CVE-2012-2113
**Name of the Vulnerable Software and Affected Versions**
libtiff versions prior to 4.0.2
**Description**
The issue involves multiple vulnerabilities in the libtiff package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service or allowing the execution of arbitrary code via a crafted TIFF image, triggering a heap-based buffer overflow.
**Recommendations**
For libtiff versions prior to 4.0.2, update to version 4.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to TIFF images from untrusted sources to minimize the risk of exploitation. Avoid using the tiff2pdf function in libtiff until the issue is resolved.