LWN.net Logo

tiff: code execution

Package(s):tiff CVE #(s):CVE-2013-4243
Created:September 24, 2013 Updated:September 25, 2013
Description: From the CVE entry:

Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image.

Alerts:
openSUSE openSUSE-SU-2013:1482-1 2013-09-24
Mageia MGASA-2013-0291 2013-09-24
openSUSE openSUSE-SU-2013:1484-1 2013-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds