CVE-2012-3444: Buffer Overflow
The getimagedimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.
Other sources
The getimagedimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3444?
CVE-2012-3444 has a moderate severity rating due to the potential for denial of service caused by processing large TIFF images.
How do I fix CVE-2012-3444?
To fix CVE-2012-3444, upgrade to Django version 1.3.2 or 1.4.1 or later.
What versions of Django are affected by CVE-2012-3444?
CVE-2012-3444 affects Django versions prior to 1.3.2 and 1.4.x before 1.4.1.
What impact does CVE-2012-3444 have on systems?
CVE-2012-3444 can lead to denial of service through excessive resource consumption when handling large TIFF images.
Is there a patch available for CVE-2012-3444?
Yes, the patch for CVE-2012-3444 is included in the updates for Django version 1.3.2 and 1.4.1.