Lucene search

K
cve[email protected]CVE-2012-4447
HistoryOct 28, 2012 - 3:55 p.m.

CVE-2012-4447

2012-10-2815:55:01
CWE-119
web.nvd.nist.gov
44
cve-2012-4447
nvd
denial of service
remote attackers
arbitrary code
tiff image
pixarlog compression format

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%

Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.

Affected configurations

NVD
Node
libtifflibtiffRange4.0.2
OR
libtifflibtiffMatch3.4
OR
libtifflibtiffMatch3.4beta18
OR
libtifflibtiffMatch3.4beta24
OR
libtifflibtiffMatch3.4beta28
OR
libtifflibtiffMatch3.4beta29
OR
libtifflibtiffMatch3.4beta31
OR
libtifflibtiffMatch3.4beta32
OR
libtifflibtiffMatch3.4beta34
OR
libtifflibtiffMatch3.4beta35
OR
libtifflibtiffMatch3.4beta36
OR
libtifflibtiffMatch3.4beta37
OR
libtifflibtiffMatch3.5.1
OR
libtifflibtiffMatch3.5.2
OR
libtifflibtiffMatch3.5.3
OR
libtifflibtiffMatch3.5.4
OR
libtifflibtiffMatch3.5.5
OR
libtifflibtiffMatch3.5.6
OR
libtifflibtiffMatch3.5.6beta
OR
libtifflibtiffMatch3.5.7
OR
libtifflibtiffMatch3.5.7alpha
OR
libtifflibtiffMatch3.5.7alpha2
OR
libtifflibtiffMatch3.5.7alpha3
OR
libtifflibtiffMatch3.5.7alpha4
OR
libtifflibtiffMatch3.5.7beta
OR
libtifflibtiffMatch3.6.0
OR
libtifflibtiffMatch3.6.0beta
OR
libtifflibtiffMatch3.6.0beta2
OR
libtifflibtiffMatch3.6.1
OR
libtifflibtiffMatch3.7.0
OR
libtifflibtiffMatch3.7.0alpha
OR
libtifflibtiffMatch3.7.0beta
OR
libtifflibtiffMatch3.7.0beta2
OR
libtifflibtiffMatch3.7.1
OR
libtifflibtiffMatch3.7.2
OR
libtifflibtiffMatch3.7.3
OR
libtifflibtiffMatch3.7.4
OR
libtifflibtiffMatch3.8.0
OR
libtifflibtiffMatch3.8.1
OR
libtifflibtiffMatch3.8.2
OR
libtifflibtiffMatch3.9
OR
libtifflibtiffMatch3.9.0
OR
libtifflibtiffMatch3.9.0beta
OR
libtifflibtiffMatch3.9.1
OR
libtifflibtiffMatch3.9.2
OR
libtifflibtiffMatch3.9.2-5.2.1
OR
libtifflibtiffMatch3.9.3
OR
libtifflibtiffMatch3.9.4
OR
libtifflibtiffMatch3.9.5
OR
libtifflibtiffMatch4.0
OR
libtifflibtiffMatch4.0alpha
OR
libtifflibtiffMatch4.0beta1
OR
libtifflibtiffMatch4.0beta2
OR
libtifflibtiffMatch4.0beta3
OR
libtifflibtiffMatch4.0beta4
OR
libtifflibtiffMatch4.0beta5
OR
libtifflibtiffMatch4.0beta6
OR
libtifflibtiffMatch4.0.1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%