LibTIFF 't2p_read_tiff_init()' Function Heap-based Buffer Overflow Vulnerability
BID:54601
Info
LibTIFF 't2p_read_tiff_init()' Function Heap-based Buffer Overflow Vulnerability
| Bugtraq ID: | 54601 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-3401 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2012 12:00AM |
| Updated: | Apr 13 2015 10:14PM |
| Credit: | Huzaifa Sidhpurwala |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C5.11 Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Ubuntu Ubuntu Linux 8.04 LTS 0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 LibTIFF tiff2pdf 0 LibTIFF LibTIFF 4.0.2 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 |
| Not Vulnerable: |
LibTIFF LibTIFF 4.0.3 |
Discussion
LibTIFF 't2p_read_tiff_init()' Function Heap-based Buffer Overflow Vulnerability
The LibTIFF is prone to a heap-based buffer overflow vulnerability.
Successful exploits allow an attacker to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the application.
LibTIFF 4.0.2 is vulnerable; other versions may also be affected.
The LibTIFF is prone to a heap-based buffer overflow vulnerability.
Successful exploits allow an attacker to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the application.
LibTIFF 4.0.2 is vulnerable; other versions may also be affected.
Solution / Fix
LibTIFF 't2p_read_tiff_init()' Function Heap-based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva lib64tiff3-3.8.2-12.8mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff3-devel-3.8.2-12.8mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff3-static-devel-3.8.2-12.8mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.8.2-12.8mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva libtiff-progs-3.8.2-12.8mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.8.2-12.8mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-devel-3.8.2-12.8mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-static-devel-3.8.2-12.8mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva lib64tiff-devel-3.9.5-1.3-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff-static-devel-3.9.5-1.3-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff3-3.9.5-1.3-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.9.5-1.3-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva libtiff-devel-3.9.5-1.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.9.5-1.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-static-devel-3.9.5-1.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.9.5-1.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva lib64tiff-devel-4.0.1-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff-static-devel-4.0.1-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff5-4.0.1-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-4.0.1-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
LibTIFF 't2p_read_tiff_init()' Function Heap-based Buffer Overflow Vulnerability
References:
References:
- Bug 837577 - (CVE-2012-3401) CVE-2012-3401 libtiff (tiff2pdf): Heap-based buffer (Red Hat)
- LibTIFF Homepage (LibTIFF)
- TIFF CHANGE INFORMATION (RemoteSensing.org)
- tiff2pdf: Heap-based buffer overflow due to improper initialization of T2P conte (Solar Designer)
- Xerox Security Bulletin XRX13-003 (Xerox)
- Xerox Security Bulletin XRX13-004 (Xerox)