[Forgot Password]
Login  Register Subscribe

23631

 
 

119105

 
 

98250

 
 

909

 
 

79281

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2012-3401

Date: (C)2012-08-13   (M)2017-11-18 


The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.

CVSS Score: 6.8Access Vector: NETWORK
Exploit Score: 8.6Access Complexity: MEDIUM
Impact Score: 6.4Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL





Reference:
SECUNIA-49938
SECUNIA-50007
SECUNIA-50726
BID-54601
OSVDB-84090
DSA-2552
GLSA-201209-02
MDVSA-2012:127
RHSA-2012:1590
USN-1511-1
http://www.openwall.com/lists/oss-security/2012/07/19/4
http://www.openwall.com/lists/oss-security/2012/07/19/1
http://libjpeg-turbo.svn.sourceforge.net/viewvc/libjpeg-turbo?view=revision&revision=830
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
https://bugzilla.redhat.com/attachment.cgi?id=596457
https://bugzilla.redhat.com/show_bug.cgi?id=837577
libtiff-t2preadtiffinit-bo(77088)
openSUSE-SU-2012:0955

CPE    57
cpe:/a:libtiff:libtiff:4.0.2
cpe:/a:libtiff:libtiff:3.9.2-5.2.1
cpe:/a:libtiff:libtiff:4.0.1
cpe:/a:libtiff:libtiff:4.0:alpha
...
CWE    1
CWE-119
OVAL    13
oval:org.secpod.oval:def:104043
oval:org.secpod.oval:def:104005
oval:org.secpod.oval:def:1300108
oval:org.secpod.oval:def:302943
...

© 2013 SecPod Technologies