CVE-2012-4447
Publication date 28 October 2012
Last updated 24 July 2024
Ubuntu priority
Description
Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tiff3 | 14.04 LTS trusty | Not in release |
| tiff | 14.04 LTS trusty |
Not affected
|
Notes
mdeslaur
as of 2012-10-05, patch may be incomplete. See oss-security discussion. incomplete fix in 4.0.2
Patch details
| Package | Patch details |
|---|---|
| tiff3 | |
| tiff |
References
Related Ubuntu Security Notices (USN)
- USN-1631-1
- LibTIFF vulnerabilities
- 15 November 2012