Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Imageio | — | Apply OS X security update 2012-004Upgrade macOS to the latest version | Sep 27, 2012 | Jun 4, 2012 |
| Apple Osx Note | — | Apply OS X security update 2012-004Upgrade macOS to the latest version | Aug 28, 2015 | Jun 4, 2012 |
| Centos_linux | — | Upgrade libtiff-develUpgrade libtiffUpgrade libtiff-static | Dec 1, 2016 | Jun 4, 2012 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jun 4, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 30, 2015 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jun 4, 2012 |
| Oracle Solaris | — | Upgrade image/library/libtiff to version 3.9.5-0.175.0.8.0.2.0 on Solaris 11.0 | May 29, 2017 | Jun 4, 2012 |
| Oracle_linux | — | Upgrade libtiff-develUpgrade libtiff-staticUpgrade libtiff | Oct 16, 2024 | Jun 4, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 4, 2012 |
| Suse | — | Upgrade libtiff-devel-32bitUpgrade libtiff-develUpgrade libtiff-devel-docsUpgrade libtiff6Upgrade tiff-docsUpgrade libtiff5Upgrade libtiff5-32bitUpgrade libtiff3-32bitUpgrade tiffUpgrade libtiff3-x86Upgrade libtiff3 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libtiff4 | Nov 8, 2024 | Jun 4, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub