LWN.net Logo

tiff: code execution

Package(s):tiff CVE #(s):CVE-2012-3401
Created:July 19, 2012 Updated:August 10, 2012
Description:

From the Ubuntu advisory:

Huzaifa Sidhpurwala discovered that the tiff2pdf utility incorrectly handled certain malformed TIFF images. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges.

Alerts:
Ubuntu USN-1511-1 2012-07-19
Mageia MGASA-2012-0181 2012-07-24
Fedora FEDORA-2012-11000 2012-07-26
openSUSE openSUSE-SU-2012:0955-1 2012-08-06
Mandriva MDVSA-2012:127 2012-08-08
Fedora FEDORA-2012-10978 2012-08-09
Gentoo 201209-02 2012-09-23
Debian DSA-2552-1 2012-09-26
Red Hat RHSA-2012:1590-01 2012-12-18
CentOS CESA-2012:1590 2012-12-19
CentOS CESA-2012:1590 2012-12-19
Oracle ELSA-2012-1590 2012-12-18
Oracle ELSA-2012-1590 2012-12-19
Scientific Linux SL-libt-20121219 2012-12-19
Mandriva MDVSA-2013:046 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds