LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
BID:54076
Info
LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
| Bugtraq ID: | 54076 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-2113 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2012 12:00AM |
| Updated: | Apr 13 2015 09:42PM |
| Credit: | Reported by Karel Volný in a Red Hat bug report. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Suse Linux Enterprise Desktop 11 SP1 SuSE Suse Linux Enterprise Desktop 10 SP4 Slackware Linux x86_64 -current Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux -current Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 LibTIFF LibTIFF 4.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Proactive Contact 5.0 Avaya IQ 4.1 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IQ 4.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1.1 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 SP2 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 |
| Not Vulnerable: |
LibTIFF LibTIFF 4.0.2 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 Avaya Aura Session Manager 6.3 Avaya Aura Presence Services 6.1.2 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Application Server 5300 SIP Core 3.0 PB3 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 |
Discussion
LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
LibTIFF is prone to a remote integer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits allow an attackers to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the application.
Versions prior to LibTIFF 4.0.2 are vulnerable.
LibTIFF is prone to a remote integer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits allow an attackers to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the application.
Versions prior to LibTIFF 4.0.2 are vulnerable.
Exploit / POC
LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
An attacker can exploit these issues through a browser.
An attacker can exploit these issues through a browser.
Solution / Fix
LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
Slackware Linux 13.1
Slackware Linux x86_64 -current
Slackware Linux 14.0 x86_64
MandrakeSoft Enterprise Server 5
Slackware Linux 13.0 x86_64
Mandriva Linux Mandrake 2011
Slackware Linux 13.37
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware libtiff-3.9.7-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ libtiff-3.9.7-i486-1_slack12.2.tgz
Slackware Linux 13.1
-
Slackware libtiff-3.9.7-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ libtiff-3.9.7-i486-1_slack13.1.txz
Slackware Linux x86_64 -current
-
Slackware libtiff-3.9.7-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/libtiff-3.9.7-x86_64-1.txz
Slackware Linux 14.0 x86_64
-
Slackware libtiff-3.9.7-x86_64-1_slack14.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/package s/libtiff-3.9.7-x86_64-1_slack14.0.txz
MandrakeSoft Enterprise Server 5
-
Mandriva libtiff-progs-3.8.2-12.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.8.2-12.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-devel-3.8.2-12.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-static-devel-3.8.2-12.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.0 x86_64
-
Slackware libtiff-3.9.7-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/libtiff-3.9.7-x86_64-1_slack13.0.txz
Mandriva Linux Mandrake 2011
-
Mandriva libtiff-devel-3.9.5-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.9.5-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-static-devel-3.9.5-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.9.5-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.37
-
Slackware libtiff-3.9.7-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /libtiff-3.9.7-i486-1_slack13.37.txz
References
LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
References:
References:
- LibTIFF Homepage (LibTIFF)
- TIFF CHANGE INFORMATION: tiff2pdf Integer Overflow Vulnerability (LibTIFF)
- ASA-2012-394: libtiff security update (RHSA-2012-1054) (Avaya)
- Bug 810551 - (CVE-2012-2113) libtiff: integer overflow in tiff2pdf : 810551 (Red Hat Security Response Team)