PT-2013-1163 · Libtiff+4 · Libtiff+4

Emmanuel Bouillon

·

Published

2013-05-02

·

Updated

2024-06-15

·

CVE-2013-1961

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libtiff versions prior to 4.0.3
Description The issue is related to multiple vulnerabilities in the libtiff package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability is a stack-based buffer overflow in the t2p write pdf page function in tiff2pdf in libtiff before 4.0.3, allowing remote attackers to cause a denial of service (application crash) via a crafted image length and resolution in a TIFF image file.
Recommendations For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the t2p write pdf page function in tiff2pdf until a patch is available. Avoid using crafted TIFF image files that could exploit the buffer overflow vulnerability until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1628
BDU:2015-06338
BDU:2015-06339
BDU:2015-06340
BDU:2015-06344
BDU:2015-06345
BDU:2015-08609
BDU:2015-08610
BDU:2015-08611
BDU:2015-08612
BDU:2015-09010
BDU:2015-09718
CESA-2014_0222
CVE-2013-1961
DLA-610-1
DSA-2698-1
OPENSUSE-SU-2024:10554-1
RHSA-2014:0222
RHSA-2014:0223
RHSA-2014_0222
RHSA-2014_0223
USN-1832-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Libtiff