PT-2013-1809 · Libtiff+3 · Libtiff+3
Huzaifa S. Sidhpurwala
·
Published
2012-12-18
·
Updated
2023-02-13
·
CVE-2012-5581
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LibTIFF versions prior to 4.0.2
Description
The issue is related to a stack-based buffer overflow in the tif dir.c file, which can be triggered by a crafted DOTRANGE tag in a TIFF image. This can cause a denial of service, resulting in a crash, and potentially allow the execution of arbitrary code.
Recommendations
For versions prior to 4.0.2, update to version 4.0.2 or later to resolve the issue.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Libtiff
Red Hat
Suse