CVE-2012-3401

Publication date 19 July 2012

Last updated 24 July 2024


Ubuntu priority

The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.

Read the notes from the security team

Status

Package Ubuntu Release Status
tiff 12.04 LTS precise
Fixed 3.9.5-2ubuntu1.2
11.10 oneiric
Fixed 3.9.5-1ubuntu1.3
11.04 natty
Fixed 3.9.4-5ubuntu6.3
10.04 LTS lucid
Fixed 3.9.2-2ubuntu0.10
8.04 LTS hardy
Fixed 3.8.2-7ubuntu3.13
tiff3 12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Notes


mdeslaur

not included in 4.0.2 tiff2pdf is not packaged in tiff3 in quantal

References

Related Ubuntu Security Notices (USN)

Other references