Revision:  454837
Date:      2017-11-24
Time:      19:28:57Z
Committer: joneum

313da7dc-763b-11df-bcce-0018f3e2eb82tiff -- buffer overflow vulnerability

Kevin Finisterre reports:

Multiple integer overflows in the handling of TIFF files may result in a heap buffer overflow. Opening a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution. The issues are addressed through improved bounds checking. Credit to Kevin Finisterre of for reporting these issues.

Discovery 2010-04-15
Entry 2010-06-12
lt 3.9.3

lt 3.9.3

8816bf3a-7929-11df-bcce-0018f3e2eb82tiff -- Multiple integer overflows

Tielei Wang:

Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.

Discovery 2009-05-22
Entry 2010-06-16
lt 3.9.4

lt 3.9.4