CVE-2011-0192
Summary
| CVE | CVE-2011-0192 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-03 20:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h. NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Itunes | 10.0 | All | All | All |
| Application | Apple | Itunes | 10.0.1 | All | All | All |
| Application | Apple | Itunes | 10.1 | All | All | All |
| Application | Apple | Itunes | 10.1.1 | All | All | All |
| Application | Apple | Itunes | 4.0.0 | All | All | All |
| Application | Apple | Itunes | 4.0.1 | All | All | All |
| Application | Apple | Itunes | 4.1.0 | All | All | All |
| Application | Apple | Itunes | 4.2.0 | All | All | All |
| Application | Apple | Itunes | 4.5 | All | All | All |
| Application | Apple | Itunes | 4.5.0 | All | All | All |
| Application | Apple | Itunes | 4.6 | All | All | All |
| Application | Apple | Itunes | 4.6.0 | All | All | All |
| Application | Apple | Itunes | 4.7 | All | All | All |
| Application | Apple | Itunes | 4.7.0 | All | All | All |
| Application | Apple | Itunes | 4.7.1 | All | All | All |
| Application | Apple | Itunes | 4.7.2 | All | All | All |
| Application | Apple | Itunes | 4.8.0 | All | All | All |
| Application | Apple | Itunes | 4.9.0 | All | All | All |
| Application | Apple | Itunes | 5.0 | All | All | All |
| Application | Apple | Itunes | 5.0.0 | All | All | All |
| Application | Apple | Itunes | 5.0.1 | All | All | All |
| Application | Apple | Itunes | 6.0.0 | All | All | All |
| Application | Apple | Itunes | 6.0.1 | All | All | All |
| Application | Apple | Itunes | 6.0.2 | All | All | All |
| Application | Apple | Itunes | 6.0.3 | All | All | All |
| Application | Apple | Itunes | 6.0.4 | All | All | All |
| Application | Apple | Itunes | 6.0.4.2 | All | All | All |
| Application | Apple | Itunes | 6.0.5 | All | All | All |
| Application | Apple | Itunes | 7.0.0 | All | All | All |
| Application | Apple | Itunes | 7.0.1 | All | All | All |
| Application | Apple | Itunes | 7.0.2 | All | All | All |
| Application | Apple | Itunes | 7.1.0 | All | All | All |
| Application | Apple | Itunes | 7.1.1 | All | All | All |
| Application | Apple | Itunes | 7.2.0 | All | All | All |
| Application | Apple | Itunes | 7.3.0 | All | All | All |
| Application | Apple | Itunes | 7.3.1 | All | All | All |
| Application | Apple | Itunes | 7.3.2 | All | All | All |
| Application | Apple | Itunes | 7.4 | All | All | All |
| Application | Apple | Itunes | 7.4.0 | All | All | All |
| Application | Apple | Itunes | 7.4.1 | All | All | All |
| Application | Apple | Itunes | 7.4.2 | All | All | All |
| Application | Apple | Itunes | 7.4.3 | All | All | All |
| Application | Apple | Itunes | 7.5 | All | All | All |
| Application | Apple | Itunes | 7.5.0 | All | All | All |
| Application | Apple | Itunes | 7.6 | All | All | All |
| Application | Apple | Itunes | 7.6.0 | All | All | All |
| Application | Apple | Itunes | 7.6.1 | All | All | All |
| Application | Apple | Itunes | 7.6.2 | All | All | All |
| Application | Apple | Itunes | 7.7 | All | All | All |
| Application | Apple | Itunes | 7.7.0 | All | All | All |
| Application | Apple | Itunes | 7.7.1 | All | All | All |
| Application | Apple | Itunes | 8.0.0 | All | All | All |
| Application | Apple | Itunes | 8.0.1 | All | All | All |
| Application | Apple | Itunes | 8.0.2 | All | All | All |
| Application | Apple | Itunes | 8.1 | All | All | All |
| Application | Apple | Itunes | 8.1.1 | All | All | All |
| Application | Apple | Itunes | 8.2 | All | All | All |
| Application | Apple | Itunes | 8.2.1 | All | All | All |
| Application | Apple | Itunes | 9.0.0 | All | All | All |
| Application | Apple | Itunes | 9.0.1 | All | All | All |
| Application | Apple | Itunes | 9.0.2 | All | All | All |
| Application | Apple | Itunes | 9.0.3 | All | All | All |
| Application | Apple | Itunes | 9.2 | All | All | All |
| Application | Apple | Itunes | 9.2.1 | All | All | All |
| Application | Apple | Itunes | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Microsoft | Windows 7 | All | All | All | All |
| Operating System | Microsoft | Windows Vista | All | All | All | All |
| Operating System | Microsoft | Windows Vista | All | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| About the security content of iTunes 10.2 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| About the security content of Safari 5.0.4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Fedora update for libtiff - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| About the security content of iOS 5 Software Update | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| APPLE-SA-2011-10-12-2 Apple TV Software Update 4.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| KB27244-Vulnerabilities in BlackBerry Enterprise Server components that process images could allow remote code execution | af854a3a-2127-422b-91ae-364da2661108 | blackberry.com | |
| Red Hat update for libtiff - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:009 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| LibTIFF Heap Overflow in Processing CCITT Group 4 Encoded TIFF Images Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| APPLE-SA-2011-03-09-1 iOS 4.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of Apple TV 4.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| LibTIFF Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 13 Update: libtiff-3.9.4-4.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 14 Update: libtiff-3.9.4-4.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| APPLE-SA-2011-10-12-1 iOS 5 Software Update | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| [SECURITY] Fedora 14 Update: libtiff-3.9.4-3.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian update for tiff - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2011-03-02-1 iTunes 10.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:005 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| APPLE-SA-2011-03-09-2 Safari 5.0.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | |
| Support / Security / Advisories / / MDVSA-2011:043 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| About the security content of Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 678635 – (CVE-2011-0192) CVE-2011-0192 libtiff: buffer overflow in Fax4Decode | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| About the security content of Apple TV Software Update 4.4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| APPLE-SA-2011-03-09-3 Apple TV 4.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Debian -- Security Information -- DSA-2210-1 tiff | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| About the security content of iOS 4.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| [SECURITY] Fedora 15 Update: libtiff-3.9.4-3.fc15 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Fedora update for libtiff - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Security Advisory SA50726 - Gentoo update for tiff - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- libTIFF: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Slackware update for libtiff - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.