Lucene search

K
cve[email protected]CVE-2013-1960
HistoryJul 03, 2013 - 6:55 p.m.

CVE-2013-1960

2013-07-0318:55:00
CWE-119
web.nvd.nist.gov
52
cve-2013-1960
nvd
libtiff
buffer overflow
t2p_process_jpeg_strip
denial of service
remote attack
arbitrary code execution
tiff image file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.8 High

AI Score

Confidence

High

0.044 Low

EPSS

Percentile

92.5%

Heap-based buffer overflow in the t2p_process_jpeg_strip function in tiff2pdf in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image file.

Affected configurations

NVD
Node
remotesensinglibtiffRange4.0.3
OR
remotesensinglibtiffMatch3.4
OR
remotesensinglibtiffMatch3.4beta18
OR
remotesensinglibtiffMatch3.4beta24
OR
remotesensinglibtiffMatch3.4beta28
OR
remotesensinglibtiffMatch3.4beta29
OR
remotesensinglibtiffMatch3.4beta31
OR
remotesensinglibtiffMatch3.4beta32
OR
remotesensinglibtiffMatch3.4beta34
OR
remotesensinglibtiffMatch3.4beta35
OR
remotesensinglibtiffMatch3.4beta36
OR
remotesensinglibtiffMatch3.4beta37
OR
remotesensinglibtiffMatch3.5.1
OR
remotesensinglibtiffMatch3.5.2
OR
remotesensinglibtiffMatch3.5.3
OR
remotesensinglibtiffMatch3.5.4
OR
remotesensinglibtiffMatch3.5.5
OR
remotesensinglibtiffMatch3.5.6
OR
remotesensinglibtiffMatch3.5.6beta
OR
remotesensinglibtiffMatch3.5.7
OR
remotesensinglibtiffMatch3.5.7alpha
OR
remotesensinglibtiffMatch3.5.7alpha2
OR
remotesensinglibtiffMatch3.5.7alpha3
OR
remotesensinglibtiffMatch3.5.7alpha4
OR
remotesensinglibtiffMatch3.5.7beta
OR
remotesensinglibtiffMatch3.6.0
OR
remotesensinglibtiffMatch3.6.0beta
OR
remotesensinglibtiffMatch3.6.0beta2
OR
remotesensinglibtiffMatch3.6.1
OR
remotesensinglibtiffMatch3.7.0
OR
remotesensinglibtiffMatch3.7.0alpha
OR
remotesensinglibtiffMatch3.7.0beta
OR
remotesensinglibtiffMatch3.7.0beta2
OR
remotesensinglibtiffMatch3.7.1
OR
remotesensinglibtiffMatch3.7.2
OR
remotesensinglibtiffMatch3.7.3
OR
remotesensinglibtiffMatch3.7.4
OR
remotesensinglibtiffMatch3.8.0
OR
remotesensinglibtiffMatch3.8.1
OR
remotesensinglibtiffMatch3.8.2
OR
remotesensinglibtiffMatch3.9.0
OR
remotesensinglibtiffMatch3.9.0beta
OR
remotesensinglibtiffMatch3.9.1
OR
remotesensinglibtiffMatch3.9.2
OR
remotesensinglibtiffMatch3.9.3
OR
remotesensinglibtiffMatch3.9.4
OR
remotesensinglibtiffMatch4.0.0
OR
remotesensinglibtiffMatch4.0.1
OR
remotesensinglibtiffMatch4.0.2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.8 High

AI Score

Confidence

High

0.044 Low

EPSS

Percentile

92.5%