Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a negative tile depth in a tiff image, which triggers an improper conversion between signed and unsigned types, leading to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tiff | Aug 30, 2017 | Jul 22, 2012 |
| Apple Osx Imageio | — | Upgrade macOS to the latest versionApply OS X security update 2013-001 | Apr 3, 2013 | Jul 22, 2012 |
| Apple Osx Note | — | Apply OS X security update 2013-001Apply OS X security update 2013-002Upgrade macOS to the latest version | Aug 28, 2015 | Jul 22, 2012 |
| Centos_linux | — | Upgrade libtiff-staticUpgrade libtiffUpgrade libtiff-devel | Dec 1, 2016 | Jul 22, 2012 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jul 22, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 30, 2015 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jul 22, 2012 |
| Oracle Solaris | — | Upgrade image/library/libtiff to version 3.9.5-0.175.0.10.0.4.0 on Solaris 11.0Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Jul 22, 2012 |
| Oracle_linux | — | Upgrade libtiff-staticUpgrade libtiffUpgrade libtiff-devel | Oct 16, 2024 | Jul 22, 2012 |
| Suse | — | Upgrade tiffUpgrade libtiff3Upgrade libtiff3-x86Upgrade libtiff-develUpgrade libtiff3-32bitUpgrade libtiff-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libtiff-toolsUpgrade libtiff4 | Nov 8, 2024 | Jul 22, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub