CVE-2012-4564
Publication date 11 November 2012
Last updated 24 July 2024
Ubuntu priority
Description
ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
tiff | 14.04 LTS trusty |
Fixed 4.0.2-4ubuntu2
|
tiff3 | 14.04 LTS trusty | Not in release |
References
Related Ubuntu Security Notices (USN)
- USN-1631-1
- LibTIFF vulnerabilities
- 15 November 2012