PT-2013-1163 · Libtiff+4 · Libtiff+4

Emmanuel Bouillon

·

Publicado

2013-05-02

·

Atualizado

2024-06-15

·

CVE-2013-1961

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libtiff versions prior to 4.0.3
Description The issue is related to multiple vulnerabilities in the libtiff package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability is a stack-based buffer overflow in the t2p write pdf page function in tiff2pdf in libtiff before 4.0.3, allowing remote attackers to cause a denial of service (application crash) via a crafted image length and resolution in a TIFF image file.
Recommendations For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the t2p write pdf page function in tiff2pdf until a patch is available. Avoid using crafted TIFF image files that could exploit the buffer overflow vulnerability until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Correção

DoS

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1628
BDU:2015-06338
BDU:2015-06339
BDU:2015-06340
BDU:2015-06344
BDU:2015-06345
BDU:2015-08609
BDU:2015-08610
BDU:2015-08611
BDU:2015-08612
BDU:2015-09010
BDU:2015-09718
CESA-2014_0222
CVE-2013-1961
DLA-610-1
DSA-2698-1
OPENSUSE-SU-2024:10554-1
RHSA-2014:0222
RHSA-2014:0223
RHSA-2014_0222
RHSA-2014_0223
USN-1832-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Libtiff