CVE-2012-2113: Buffer Overflow
Description of problem:
Version-Release number of selected component (if applicable): libtiff-3.9.4-5.el62
How reproducible: always
Steps to Reproduce: 1. tiff2pdf poc.tif (where poc.tif is the file provided for testing CVE-2012-1173)
Actual results: tiff2pdf poc.tif II%PDF-1.1 %���� 1 0 obj << /Type /Catalog /Pages 3 0 R > endobj 2 0 obj << /CreationDate (D:20120406113719) /ModDate (D:20120406113719) /Producer (libtiff / tiff2pdf - 20100615) > endobj 3 0 obj << /Type /Pages /Kids [ 4 0 R ] /Count 1 > endobj 4 0 obj << /Type /Page /Parent 3 0 R /MediaBox [0.0000 0.0000 192.0000 145.6800] /Contents 5 0 R /Resources << /XObject << /Im11 7 0 R /Im12 9 0 R /Im13 11 0 R >> /ProcSet [ /ImageC ] > > endobj 5 0 obj << /Length 6 0 R >> stream q 192.0000 0.0000 0.0000 61.4400 0.0000 84.2400 cm /Im11 Do Q q 192.0000 0.0000 0.0000 61.4400 0.0000 22.8000 cm /Im12 Do Q q 192.0000 0.0000 0.0000 22.8000 0.0000 0.0000 cm /Im13 Do Q
endstream endobj 6 0 obj 191 endobj 7 0 obj << /Length 8 0 R /Type /XObject /Subtype /Image /Name /Im11 /Width 800 /Height 256 /BitsPerComponent 8 /ColorSpace /DeviceRGB >> stream Segmentation fault (core dumped)
Expected results: (some sane error message, no segfault)
Additional info: This affects also RHEL5.
Other sources
Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2113?
CVE-2012-2113 is classified as a moderate severity vulnerability.
How do I fix CVE-2012-2113?
To fix CVE-2012-2113, you should update to a patched version of libtiff that addresses the vulnerability.
What types of systems are affected by CVE-2012-2113?
CVE-2012-2113 affects systems running affected versions of the libtiff library.
What CVSS score does CVE-2012-2113 have?
CVE-2012-2113 has a CVSS score that indicates the impact and exploitability of the vulnerability.
Is CVE-2012-2113 still relevant for current systems?
CVE-2012-2113 remains relevant for systems using outdated versions of libtiff.