CVE-2012-4447: Buffer Overflow
A heap-based buffer overflow was found in the way libtiff, library for manipulating TIFF (Tagged Image File Format) image format files, processed certain TIFF images using PixarLog Compression format. An attacker could create a specially-crafted TIFF image that, when opened, could cause an application using libtiff to crash or, possibly, execute arbitrary code with the privileges of the user running the application.
Other sources
Heap-based buffer overflow in tifpixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4447?
CVE-2012-4447 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2012-4447?
To fix CVE-2012-4447, you should upgrade to a version of libtiff that is newer than 4.0.2 or 3.9.5.
What types of software are affected by CVE-2012-4447?
CVE-2012-4447 affects various versions of the libtiff library used for handling TIFF image files.
What kind of attacks can exploit CVE-2012-4447?
Attackers can exploit CVE-2012-4447 by crafting malicious TIFF images that may lead to application crashes or arbitrary code execution.
Is CVE-2012-4447 still relevant today?
Yes, CVE-2012-4447 remains relevant as outdated systems or applications using vulnerable libtiff versions can still be targeted.