LWN.net Logo

libtiff: code execution

Package(s):libtiff CVE #(s):CVE-2012-2088 CVE-2012-2113
Created:July 3, 2012 Updated:July 20, 2012
Description: From the Red Hat advisory:

libtiff did not properly convert between signed and unsigned integer values, leading to a buffer overflow. An attacker could use this flaw to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash or, possibly, execute arbitrary code. (CVE-2012-2088)

Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in the tiff2pdf tool. An attacker could use these flaws to create a specially-crafted TIFF file that would cause tiff2pdf to crash or, possibly, execute arbitrary code. (CVE-2012-2113)

Alerts:
Red Hat RHSA-2012:1054-01 2012-07-03
CentOS CESA-2012:1054 2012-07-03
Mandriva MDVSA-2012:101 2012-07-04
Oracle ELSA-2012-1054 2012-07-03
Oracle ELSA-2012-1054 2012-07-03
openSUSE openSUSE-SU-2012:0829-1 2012-07-04
Ubuntu USN-1498-1 2012-07-05
Scientific Linux SL-libt-20120705 2012-07-05
Mageia MGASA-2012-0137 2012-07-09
Scientific Linux SL-libt-20120709 2012-07-09
CentOS CESA-2012:1054 2012-07-10
Fedora FEDORA-2012-10081 2012-07-15
Fedora FEDORA-2012-10089 2012-07-15
SUSE SUSE-SU-2012:0894-1 2012-07-19
Gentoo 201209-02 2012-09-23
Debian DSA-2552-1 2012-09-26
Mandriva MDVSA-2013:046 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds