CVE-2011-0192

Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h.  NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
appleitunes
𝑥
≤ 10.1.2
appleitunes
4.0.0
appleitunes
4.0.1
appleitunes
4.1.0
appleitunes
4.2.0
appleitunes
4.5
appleitunes
4.5.0
appleitunes
4.6
appleitunes
4.6.0
appleitunes
4.7
appleitunes
4.7.0
appleitunes
4.7.1
appleitunes
4.7.2
appleitunes
4.8.0
appleitunes
4.9.0
appleitunes
5.0
appleitunes
5.0.0
appleitunes
5.0.1
appleitunes
6.0.0
appleitunes
6.0.1
appleitunes
6.0.2
appleitunes
6.0.3
appleitunes
6.0.4
appleitunes
6.0.4.2
appleitunes
6.0.5
appleitunes
7.0.0
appleitunes
7.0.1
appleitunes
7.0.2
appleitunes
7.1.0
appleitunes
7.1.1
appleitunes
7.2.0
appleitunes
7.3.0
appleitunes
7.3.1
appleitunes
7.3.2
appleitunes
7.4
appleitunes
7.4.0
appleitunes
7.4.1
appleitunes
7.4.2
appleitunes
7.4.3
appleitunes
7.5
appleitunes
7.5.0
appleitunes
7.6
appleitunes
7.6.0
appleitunes
7.6.1
appleitunes
7.6.2
appleitunes
7.7
appleitunes
7.7.0
appleitunes
7.7.1
appleitunes
8.0.0
appleitunes
8.0.1
appleitunes
8.0.2
appleitunes
8.1
appleitunes
8.1.1
appleitunes
8.2
appleitunes
8.2.1
appleitunes
9.0.0
appleitunes
9.0.1
appleitunes
9.0.2
appleitunes
9.0.3
appleitunes
9.2
appleitunes
9.2.1
appleitunes
10.0
appleitunes
10.0.1
appleitunes
10.1
appleitunes
10.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
4.5.0-6+deb12u1
fixed
bookworm (security)
4.5.0-6+deb12u1
fixed
bullseye
4.2.0-1+deb11u5
fixed
bullseye (security)
4.2.0-1+deb11u5
fixed
sid
4.5.1+git230720-5
fixed
trixie
4.5.1+git230720-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tiff
dapper
Fixed 3.7.4-1ubuntu3.9
released
hardy
Fixed 3.8.2-7ubuntu3.7
released
karmic
Fixed 3.8.2-13ubuntu0.4
released
lucid
Fixed 3.9.2-2ubuntu0.4
released
maverick
Fixed 3.9.4-2ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libtiff-devel
suse enterprise desktop 15
4.0.9-3.15
fixed
suse enterprise desktop 15 SP1
4.0.9-5.27.5
fixed
suse enterprise desktop 15 SP2
4.0.9-5.27.5
fixed
suse enterprise sap 15
4.0.9-3.15
fixed
suse enterprise sap 15 SP1
4.0.9-5.27.5
fixed
suse enterprise sap 15 SP2
4.0.9-5.27.5
fixed
suse enterprise server 15
4.0.9-3.15
fixed
suse enterprise server 15 SP1
4.0.9-5.27.5
fixed
suse enterprise server 15 SP2
4.0.9-5.27.5
fixed
libtiff5
suse enterprise desktop 15
4.0.9-3.15
fixed
suse enterprise desktop 15 SP1
4.0.9-5.27.5
fixed
suse enterprise desktop 15 SP2
4.0.9-5.27.5
fixed
suse enterprise sap 12 SP5
4.0.9-44.30.1
fixed
suse enterprise sap 15
4.0.9-3.15
fixed
suse enterprise sap 15 SP1
4.0.9-5.27.5
fixed
suse enterprise sap 15 SP2
4.0.9-5.27.5
fixed
suse enterprise server 12 SP5
4.0.9-44.30.1
fixed
suse enterprise server 15
4.0.9-3.15
fixed
suse enterprise server 15 SP1
4.0.9-5.27.5
fixed
suse enterprise server 15 SP2
4.0.9-5.27.5
fixed
libtiff5-32bit
suse enterprise sap 12 SP5
4.0.9-44.30.1
fixed
suse enterprise server 12 SP5
4.0.9-44.30.1
fixed
tiff
suse enterprise sap 12 SP5
4.0.9-44.30.1
fixed
suse enterprise server 12 SP5
4.0.9-44.30.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libtiff
RHEL 6
0:3.9.4-1.el6_0.1
fixed
libtiff-devel
RHEL 6
0:3.9.4-1.el6_0.1
fixed
libtiff-static
RHEL 6
0:3.9.4-1.el6_0.1
fixed
References