CVE-2012-4564
11.11.2012, 13:00
ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow.Enginsight
Vendor | Product | Version |
---|---|---|
libtiff | libtiff | 𝑥 ≤ 4.0.3 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 11.10 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 12.10 |
redhat | enterprise_linux_desktop | 5.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_eus | 6.3 |
redhat | enterprise_linux_server | 5.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 5.0 |
redhat | enterprise_linux_workstation | 6.0 |
opensuse | opensuse | 11.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
tiff |
| ||||||||||||||||
tiff3 |
|
References