Back to search
CVE-2012-2088
Published: Jul 22, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a negative tile depth in a tiff image, which triggers an improper conversion between signed and unsigned types, leading to a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://support.apple.com/kb/HT6163
x_refsource_CONFIRM
openSUSE-SU-2012:0829
vendor-advisory
x_refsource_SUSE
SUSE-SU-2012:0894
vendor-advisory
x_refsource_SUSE
RHSA-2012:1054
vendor-advisory
x_refsource_REDHAT
54270
vdb-entry
x_refsource_BID
APPLE-SA-2013-03-14-1
vendor-advisory
x_refsource_APPLE
GLSA-201209-02
vendor-advisory
x_refsource_GENTOO
http://support.apple.com/kb/HT6162
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=832864
x_refsource_MISC
MDVSA-2012:101
vendor-advisory
x_refsource_MANDRIVA
49686
third-party-advisory
x_refsource_SECUNIA
50726
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now