LibTIFF TIFF Image Heap Buffer Overflow Vulnerability
BID:55673
Info
LibTIFF TIFF Image Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 55673 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-4447 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2012 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | Huzaifa Sidhpurwala |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux -current Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 MR3 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.0 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR4 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server for Exchange 5.0 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 MR4 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 MR3 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 Research In Motion Blackberry Enterprise Server for Domino 5.0.1 Research In Motion Blackberry Enterprise Server for Domino 5.0 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.0 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.3 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.0 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 |
| Not Vulnerable: | |
Discussion
LibTIFF TIFF Image Heap Buffer Overflow Vulnerability
LibTIFF is prone to a heap-based buffer overflow vulnerability.
Successful exploits allow an attacker to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the application.
LibTIFF 4.0.2 is vulnerable; other versions may also be affected.
LibTIFF is prone to a heap-based buffer overflow vulnerability.
Successful exploits allow an attacker to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the application.
LibTIFF 4.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
LibTIFF TIFF Image Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
LibTIFF TIFF Image Heap Buffer Overflow Vulnerability
Solution:
Reportedly, the issue have been fixed, however, Symantec has not confirmed it. Please contact the vendor for more information.
Slackware Linux -current
Slackware Linux 12.2
Slackware Linux 13.1 x86_64
Slackware Linux 13.1
Slackware Linux 12.1
Slackware Linux x86_64 -current
MandrakeSoft Enterprise Server 5 x86_64
Slackware Linux 14.0 x86_64
MandrakeSoft Enterprise Server 5
Slackware Linux 13.0 x86_64
Slackware Linux 13.37 x86_64
Slackware Linux 13.0
Mandriva Linux Mandrake 2011 x86_64
Solution:
Reportedly, the issue have been fixed, however, Symantec has not confirmed it. Please contact the vendor for more information.
Slackware Linux -current
-
Slackware libtiff-3.9.7-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/li btiff-3.9.7-i486-1.txz
Slackware Linux 12.2
-
Slackware libtiff-3.9.7-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ libtiff-3.9.7-i486-1_slack12.2.tgz
Slackware Linux 13.1 x86_64
-
Slackware libtiff-3.9.7-x86_64-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/package s/libtiff-3.9.7-x86_64-1_slack13.1.txz
Slackware Linux 13.1
-
Slackware libtiff-3.9.7-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ libtiff-3.9.7-i486-1_slack13.1.txz
Slackware Linux 12.1
-
Slackware libtiff-3.9.7-i486-1_slack12.1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/ libtiff-3.9.7-i486-1_slack12.1.tgz
Slackware Linux x86_64 -current
-
Slackware libtiff-3.9.7-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/libtiff-3.9.7-x86_64-1.txz
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva lib64tiff3-3.8.2-12.9mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff3-devel-3.8.2-12.9mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff3-static-devel-3.8.2-12.9mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.8.2-12.9mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 14.0 x86_64
-
Slackware libtiff-3.9.7-x86_64-1_slack14.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/package s/libtiff-3.9.7-x86_64-1_slack14.0.txz
MandrakeSoft Enterprise Server 5
-
Mandriva libtiff-progs-3.8.2-12.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-3.8.2-12.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-devel-3.8.2-12.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff3-static-devel-3.8.2-12.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.0 x86_64
-
Slackware libtiff-3.9.7-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/libtiff-3.9.7-x86_64-1_slack13.0.txz
Slackware Linux 13.37 x86_64
-
Slackware libtiff-3.9.7-x86_64-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packag es/libtiff-3.9.7-x86_64-1_slack13.37.txz
Slackware Linux 13.0
-
Slackware libtiff-3.9.7-i486-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/ libtiff-3.9.7-i486-1_slack13.0.txz
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva lib64tiff-devel-3.9.5-1.4-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff-static-devel-3.9.5-1.4-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64tiff3-3.9.5-1.4-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libtiff-progs-3.9.5-1.4-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
LibTIFF TIFF Image Heap Buffer Overflow Vulnerability
References:
References:
- BSRT-2013-003 Vulnerabilities in BlackBerry Enterprise Server components that pr (Research In Motion)
- LibTIFF Homepage (LibTIFF)
- libtiff: Heap-buffer overflow when processing a TIFF image with PixarLog Compres (Huzaifa S. Sidhpurwala)
- TIFF CHANGE INFORMATION (RemoteSensing.org)