Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1173

Опубликовано: 04 апр. 2012
Источник: redhat
CVSS2: 6.8

Описание

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4libtiffWill not fix
Red Hat Enterprise Linux 5libtiffFixedRHSA-2012:046810.04.2012
Red Hat Enterprise Linux 6libtiffFixedRHSA-2012:046810.04.2012

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=803078libtiff: Heap-buffer overflow due to TileSize calculation when parsing tiff files

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

nvd
около 13 лет назад

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

debian
около 13 лет назад

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow r ...

github
больше 3 лет назад

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

oracle-oval
больше 13 лет назад

ELSA-2012-0468: libtiff security update (IMPORTANT)

6.8 Medium

CVSS2