Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a negative tile depth in a tiff image, which triggers an improper conversion between signed and unsigned types, leading to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tiff | Aug 30, 2017 | Jul 22, 2012 |
| Apple Osx Imageio | — | Upgrade macOS to the latest versionApply OS X security update 2013-001 | Apr 3, 2013 | Jul 22, 2012 |
| Apple Osx Note | — | Apply OS X security update 2013-002Upgrade macOS to the latest versionApply OS X security update 2013-001 | Aug 28, 2015 | Jul 22, 2012 |
| Centos_linux | — | Upgrade libtiff-develUpgrade libtiffUpgrade libtiff-static | Dec 1, 2016 | Jul 22, 2012 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jul 22, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 30, 2015 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jul 22, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2Upgrade image/library/libtiff to version 3.9.5-0.175.0.10.0.4.0 on Solaris 11.0 | May 29, 2017 | Jul 22, 2012 |
| Oracle_linux | — | Upgrade libtiff-develUpgrade libtiff-staticUpgrade libtiff | Oct 16, 2024 | Jul 22, 2012 |
| Suse | — | Upgrade tiffUpgrade libtiff3-32bitUpgrade libtiff-develUpgrade libtiff3Upgrade libtiff-devel-32bitUpgrade libtiff3-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libtiff4Upgrade libtiff-tools | Nov 8, 2024 | Jul 22, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub