Lucene search

K
redhatRedHatRHSA-2012:0468
HistoryApr 10, 2012 - 12:00 a.m.

(RHSA-2012:0468) Important: libtiff security update

2012-04-1000:00:00
access.redhat.com
21

0.092 Low

EPSS

Percentile

94.7%

The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Two integer overflow flaws, leading to heap-based buffer overflows, were
found in the way libtiff attempted to allocate space for a tile in a TIFF
image file. An attacker could use these flaws to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2012-1173)

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. All running applications linked
against libtiff must be restarted for this update to take effect.