Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tiff | Aug 30, 2017 | Sep 10, 2013 |
| Centos_linux | — | Upgrade libtiff-develUpgrade libtiff-staticUpgrade libtiff | Dec 1, 2016 | Sep 10, 2013 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Sep 10, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 5, 2015 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Sep 10, 2013 |
| Oracle Solaris | — | Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Sep 10, 2013 |
| Oracle_linux | — | Upgrade libtiffUpgrade libtiff-staticUpgrade libtiff-devel | Aug 2, 2016 | Sep 10, 2013 |
| Suse | — | Upgrade libtiff-develUpgrade libtiffUpgrade libtiff5-32bitUpgrade libtiff-32bitUpgrade libtiff-devel-32bitUpgrade libtiff5Upgrade libtiff3Upgrade libtiff3-32bitUpgrade sle-sdk-releaseUpgrade libtiff3-x86Upgrade tiff | Dec 12, 2013 | Sep 10, 2013 |
| Ubuntu | — | Upgrade libtiff5Upgrade libtiff4 | Nov 8, 2024 | Sep 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub