Lucene search

K
f5F5F5:K15863
HistoryJan 30, 2015 - 12:00 a.m.

K15863 : Libtiff vulnerabilities CVE-2012-1173 and CVE-2012-2088

2015-01-3000:00:00
my.f5.com
51

7.8 High

AI Score

Confidence

High

0.092 Low

EPSS

Percentile

94.7%

Security Advisory Description

CVE-2012-1173

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

CVE-2012-2088

Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a negative tile depth in a tiff image, which triggers an improper conversion between signed and unsigned types, leading to a heap-based buffer overflow.

Impact

None. The BIG-IP system has the vulnerable code installed, however there is no known method to exploit it.