Security Advisory

CVE-2012-1173

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-06-04 20:00:00
Last updated 2024-08-06 18:53:35
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.