PT-2011-1183 · Libtiff+2 · Libtiff+2

Publicado

2011-03-03

·

Atualizado

2024-06-15

·

CVE-2011-0192

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF versions 3.9.4 and possibly other versions tiff package versions prior to 4.0.2-r1
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding. This is related to the EXPAND2D macro in libtiff/tif fax3.h. Multiple vulnerabilities in the tiff package can lead to violations of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For LibTIFF version 3.9.4, consider updating to a newer version to mitigate the risk. For tiff package versions prior to 4.0.2-r1, update to version 4.0.2-r1 or later to resolve the issue. As a temporary workaround, consider restricting the use of TIFF Internet Fax image files that have been compressed using CCITT Group 4 encoding until a patch is available.

Correção

DoS

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09646
CVE-2011-0192
DSA-2210-1
OPENSUSE-SU-2024:10554-1
RHSA-2011:0318
RHSA-2011_0318

Produtos afetados

Libtiff
Red Hat
Tiff