Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tiff | Aug 30, 2017 | Nov 11, 2012 |
| Centos_linux | — | Upgrade libtiff-develUpgrade libtiff-staticUpgrade libtiff | Dec 1, 2016 | Oct 28, 2012 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Oct 28, 2012 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Oct 28, 2012 |
| Oracle_linux | — | Upgrade libtiff-staticUpgrade libtiff-develUpgrade libtiff | Oct 16, 2024 | Oct 28, 2012 |
| Suse | — | Upgrade libtiff3Upgrade libtiff-develUpgrade libtiff3-x86Upgrade tiffUpgrade libtiff-devel-32bitUpgrade libtiff3-32bit | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libtiff4Upgrade libtiff5 | Nov 8, 2024 | Oct 28, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub