cpe:/a:libtiff:libtiff:3.4 cpe:/a:libtiff:libtiff:3.4:beta18 cpe:/a:libtiff:libtiff:3.4:beta24 cpe:/a:libtiff:libtiff:3.4:beta28 cpe:/a:libtiff:libtiff:3.4:beta29 cpe:/a:libtiff:libtiff:3.4:beta31 cpe:/a:libtiff:libtiff:3.4:beta32 cpe:/a:libtiff:libtiff:3.4:beta34 cpe:/a:libtiff:libtiff:3.4:beta35 cpe:/a:libtiff:libtiff:3.4:beta36 cpe:/a:libtiff:libtiff:3.4:beta37 cpe:/a:libtiff:libtiff:3.5.1 cpe:/a:libtiff:libtiff:3.5.2 cpe:/a:libtiff:libtiff:3.5.3 cpe:/a:libtiff:libtiff:3.5.4 cpe:/a:libtiff:libtiff:3.5.5 cpe:/a:libtiff:libtiff:3.5.6 cpe:/a:libtiff:libtiff:3.5.6:beta cpe:/a:libtiff:libtiff:3.5.7 cpe:/a:libtiff:libtiff:3.5.7:alpha cpe:/a:libtiff:libtiff:3.5.7:alpha2 cpe:/a:libtiff:libtiff:3.5.7:alpha3 cpe:/a:libtiff:libtiff:3.5.7:alpha4 cpe:/a:libtiff:libtiff:3.5.7:beta cpe:/a:libtiff:libtiff:3.6.0 cpe:/a:libtiff:libtiff:3.6.0:beta cpe:/a:libtiff:libtiff:3.6.0:beta2 cpe:/a:libtiff:libtiff:3.6.1 cpe:/a:libtiff:libtiff:3.7.0 cpe:/a:libtiff:libtiff:3.7.0:alpha cpe:/a:libtiff:libtiff:3.7.0:beta cpe:/a:libtiff:libtiff:3.7.0:beta2 cpe:/a:libtiff:libtiff:3.7.1 cpe:/a:libtiff:libtiff:3.7.2 cpe:/a:libtiff:libtiff:3.7.3 cpe:/a:libtiff:libtiff:3.7.4 cpe:/a:libtiff:libtiff:3.8.0 cpe:/a:libtiff:libtiff:3.8.1 cpe:/a:libtiff:libtiff:3.8.2 cpe:/a:libtiff:libtiff:3.9 cpe:/a:libtiff:libtiff:3.9.0 cpe:/a:libtiff:libtiff:3.9.0:beta cpe:/a:libtiff:libtiff:3.9.1 cpe:/a:libtiff:libtiff:3.9.2 cpe:/a:libtiff:libtiff:3.9.2-5.2.1 cpe:/a:libtiff:libtiff:3.9.3 cpe:/a:libtiff:libtiff:3.9.4 cpe:/a:libtiff:libtiff:4.0 cpe:/a:libtiff:libtiff:4.0:alpha cpe:/a:libtiff:libtiff:4.0:beta1 cpe:/a:libtiff:libtiff:4.0:beta2 cpe:/a:libtiff:libtiff:4.0:beta3 cpe:/a:libtiff:libtiff:4.0:beta4 cpe:/a:libtiff:libtiff:4.0:beta5 cpe:/a:libtiff:libtiff:4.0:beta6 cpe:/a:libtiff:libtiff:4.0.1 cpe:/a:libtiff:libtiff:4.0.2 CVE-2012-3401 2012-08-13T16:55:08.600-04:00 2017-08-28T21:31:55.007-04:00 6.8 NETWORK MEDIUM NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2012-08-14T13:37:00.000-04:00 SECUNIA 49938 SECUNIA 50007 SECUNIA 50726 BID 54601 OSVDB 84090 DEBIAN DSA-2552 GENTOO GLSA-201209-02 MANDRIVA MDVSA-2012:127 REDHAT RHSA-2012:1590 UBUNTU USN-1511-1 MLIST [oss-security] 20120719 Re: tiff2pdf: Heap-based buffer overflow due to improper initialization of T2P context struct pointer MLIST [oss-security] 20120719 tiff2pdf: Heap-based buffer overflow due to improper initialization of T2P context struct pointer MISC http://libjpeg-turbo.svn.sourceforge.net/viewvc/libjpeg-turbo?view=revision&revision=830 CONFIRM http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf MISC https://bugzilla.redhat.com/attachment.cgi?id=596457 MISC https://bugzilla.redhat.com/show_bug.cgi?id=837577 XF libtiff-t2preadtiffinit-bo(77088) SUSE openSUSE-SU-2012:0955 The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.