CVE-2012-3401
CVE-2012-3401
The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://libjpeg-turbo.svn.sourceforge.net/viewvc/libjpeg-turbo?view=revision&revision=830http://lists.opensuse.org/opensuse-updates/2012-08/msg00011.htmlhttp://osvdb.org/84090http://rhn.redhat.com/errata/RHSA-2012-1590.htmlhttps://bugzilla.redhat.com/attachment.cgi?id=596457https://bugzilla.redhat.com/show_bug.cgi?id=837577http://secunia.com/advisories/49938http://secunia.com/advisories/50007http://secunia.com/advisories/50726http://security.gentoo.org/glsa/glsa-201209-02.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/77088http://www.debian.org/security/2012/dsa-2552