CVE-2012-5581

Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
libtifflibtiff
𝑥
≤ 4.0.1
libtifflibtiff
3.4
libtifflibtiff
3.4:beta18
libtifflibtiff
3.4:beta24
libtifflibtiff
3.4:beta28
libtifflibtiff
3.4:beta29
libtifflibtiff
3.4:beta31
libtifflibtiff
3.4:beta32
libtifflibtiff
3.4:beta34
libtifflibtiff
3.4:beta35
libtifflibtiff
3.4:beta36
libtifflibtiff
3.4:beta37
libtifflibtiff
3.5.1
libtifflibtiff
3.5.2
libtifflibtiff
3.5.3
libtifflibtiff
3.5.4
libtifflibtiff
3.5.5
libtifflibtiff
3.5.6
libtifflibtiff
3.5.6:beta
libtifflibtiff
3.5.7
libtifflibtiff
3.5.7:alpha
libtifflibtiff
3.5.7:alpha2
libtifflibtiff
3.5.7:alpha3
libtifflibtiff
3.5.7:alpha4
libtifflibtiff
3.5.7:beta
libtifflibtiff
3.6.0
libtifflibtiff
3.6.0:beta
libtifflibtiff
3.6.0:beta2
libtifflibtiff
3.6.1
libtifflibtiff
3.7.0
libtifflibtiff
3.7.0:alpha
libtifflibtiff
3.7.0:beta
libtifflibtiff
3.7.0:beta2
libtifflibtiff
3.7.1
libtifflibtiff
3.7.2
libtifflibtiff
3.7.3
libtifflibtiff
3.7.4
libtifflibtiff
3.8.0
libtifflibtiff
3.8.1
libtifflibtiff
3.8.2
libtifflibtiff
3.9
libtifflibtiff
3.9.0
libtifflibtiff
3.9.0:beta
libtifflibtiff
3.9.1
libtifflibtiff
3.9.2
libtifflibtiff
3.9.2-5.2.1
libtifflibtiff
3.9.3
libtifflibtiff
3.9.4
libtifflibtiff
3.9.5
libtifflibtiff
4.0
libtifflibtiff
4.0:alpha
libtifflibtiff
4.0:beta1
libtifflibtiff
4.0:beta2
libtifflibtiff
4.0:beta3
libtifflibtiff
4.0:beta4
libtifflibtiff
4.0:beta5
libtifflibtiff
4.0:beta6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
4.5.0-6+deb12u1
fixed
bookworm (security)
4.5.0-6+deb12u1
fixed
bullseye
4.2.0-1+deb11u5
fixed
bullseye (security)
4.2.0-1+deb11u5
fixed
sid
4.5.1+git230720-5
fixed
trixie
4.5.1+git230720-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tiff
hardy
Fixed 3.8.2-7ubuntu3.16
released
lucid
Fixed 3.9.2-2ubuntu0.12
released
oneiric
Fixed 3.9.5-1ubuntu1.5
released
precise
Fixed 3.9.5-2ubuntu1.4
released
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
not-affected
tiff3
hardy
dne
lucid
dne
oneiric
dne
precise
dne
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libtiff
RHEL 6
0:3.9.4-9.el6_3
fixed
libtiff-devel
RHEL 6
0:3.9.4-9.el6_3
fixed
libtiff-static
RHEL 6
0:3.9.4-9.el6_3
fixed