libTIFF CVE-2012-1173 Remote Code Execution Vulnerability
BID:52891
Info
libTIFF CVE-2012-1173 Remote Code Execution Vulnerability
| Bugtraq ID: | 52891 |
| Class: | Unknown |
| CVE: |
CVE-2012-1173 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2012 12:00AM |
| Updated: | Apr 13 2015 09:32PM |
| Credit: | Alexander Gavrun |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Ubuntu Ubuntu Linux 8.04 LTS 0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 11.04 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.10 Ubuntu Ubuntu Linux 10.04 LTS Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 LibTIFF LibTIFF 3.9.4 LibTIFF LibTIFF 3.9.3 LibTIFF LibTIFF 3.9.2 LibTIFF LibTIFF 3.8.2 LibTIFF LibTIFF 3.9.5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Proactive Contact 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 Apple Mac OS X Server 10.7.5 Apple Mac OS X Server 10.7.3 Apple Mac OS X Server 10.7.2 Apple Mac OS X Server 10.7.1 Apple Mac OS X Server 10.7 Apple Mac OS X Server 10.6.8 Apple Mac OS X 10.7.4 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.2 Apple Mac OS X 10.7.1 Apple Mac OS X 10.7 Apple Mac OS X 10.6.8 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 Apple Apple TV 5.0 Apple Apple TV 4.4 |
| Not Vulnerable: |
Apple Mac OS X 10.8.2 Apple Mac OS X 10.7.5 Apple iOS 6 Apple Apple TV 5.1 |
Discussion
libTIFF CVE-2012-1173 Remote Code Execution Vulnerability
libTIFF is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of an application using the affected library. Failed exploit attempts will result in a denial-of-service condition.
libTIFF is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of an application using the affected library. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
libTIFF CVE-2012-1173 Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libTIFF CVE-2012-1173 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.6.8
Apple Mac OS X 10.7.3
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2011
Apple Mac OS X Server 10.6.8
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.6.8
-
Apple SecUpd2012-004.dmg
For Mac OS X v10.6.8
http://www.apple.com/support/downloads/
Apple Mac OS X 10.7.3
-
Apple MacOSXUpdCombo10.7.5.dmg
For OS X Lion v10.7 and v10.7.3
http://www.apple.com/support/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva libtiff-progs-3.8.2-12.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.8.2-12.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-devel-3.8.2-12.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-static-devel-3.8.2-12.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva libtiff-devel-3.9.5-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.9.5-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-static-devel-3.9.5-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.9.5-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
Apple Mac OS X Server 10.6.8
-
Apple SecUpdSrvr2012-004.dmg
For Mac OS X Server v10.6.8
http://www.apple.com/support/downloads/
References
libTIFF CVE-2012-1173 Remote Code Execution Vulnerability
References:
References:
- About the security content of Apple TV 5.1 (Apple)
- LibTIFF Homepage (LibTIFF)
- Xerox Security Bulletin XRX12-009 (Xerox)
- ASA-2012-209 libtiff security update (RHSA-2012-0468) (Avaya)