6.8
CVSSv2

CVE-2011-1167

Published: 28/03/2011 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and previous versions allows remote malicious users to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 3.4

libtiff libtiff 3.7.0

libtiff libtiff 3.6.0

libtiff libtiff 3.6.1

libtiff libtiff 3.8.0

libtiff libtiff 3.7.3

libtiff libtiff 3.8.1

libtiff libtiff 3.9.3

libtiff libtiff 3.5.7

libtiff libtiff 3.8.2

libtiff libtiff 3.7.2

libtiff libtiff 3.9.2-5.2.1

libtiff libtiff 3.5.3

libtiff libtiff 3.7.1

libtiff libtiff 3.5.4

libtiff libtiff 3.5.2

libtiff libtiff

libtiff libtiff 3.9.2

libtiff libtiff 3.7.4

libtiff libtiff 3.5.5

libtiff libtiff 3.9.0

libtiff libtiff 3.5.6

libtiff libtiff 3.5.1

libtiff libtiff 3.9.1

libtiff libtiff 3.9

Vendor Advisories

Certain applications could be made to run programs as your login if they opened a specially crafted TIFF file ...
Several vulnerabilities were discovered in the TIFF manipulation and conversion library: CVE-2011-0191 A buffer overflow allows to execute arbitrary code or cause a denial of service via a crafted TIFF image with JPEG encoding This issue affects the Debian 50 Lenny package only CVE-2011-0192 A buffer overflow allows to execute arbitrary ...
Debian Bug report logs - #619614 CVE-2011-1167 Package: tiff; Maintainer for tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, 25 Mar 2011 15:33:02 UTC Severity: grave Tags: security Fixed in version tiff/394-9 Done: Jay Berkenbilt <qjb@de ...
Debian Bug report logs - #678140 Two tiff issues: CVE-2012-2113 / CVE-2012-2088 Package: tiff; Maintainer for tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 19 Jun 2012 14:09:03 UTC Severity: grave Tags: security Found in version 394-5+sque ...

References

CWE-119https://bugzilla.redhat.com/show_bug.cgi?id=684939http://www.zerodayinitiative.com/advisories/ZDI-11-107http://www.osvdb.org/71256http://www.securityfocus.com/bid/46951http://bugzilla.maptools.org/show_bug.cgi?id=2300http://www.vupen.com/english/advisories/2011/0795http://www.redhat.com/support/errata/RHSA-2011-0392.htmlhttp://secunia.com/advisories/43900http://www.vupen.com/english/advisories/2011/0860http://ubuntu.com/usn/usn-1102-1http://www.mandriva.com/security/advisories?name=MDVSA-2011:064http://www.vupen.com/english/advisories/2011/0845http://www.vupen.com/english/advisories/2011/0859http://secunia.com/advisories/43934http://www.debian.org/security/2011/dsa-2210http://www.vupen.com/english/advisories/2011/0930http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057763.htmlhttp://www.vupen.com/english/advisories/2011/0905http://www.vupen.com/english/advisories/2011/0960http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.587820http://secunia.com/advisories/44135http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057840.htmlhttp://secunia.com/advisories/44117http://blackberry.com/btsc/KB27244http://secunia.com/advisories/43974http://www.securitytracker.com/id?1025257http://securityreason.com/securityalert/8165http://support.apple.com/kb/HT5130http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://support.apple.com/kb/HT5281http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://support.apple.com/kb/HT5503http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://secunia.com/advisories/50726http://security.gentoo.org/glsa/glsa-201209-02.xmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/66247http://www.securityfocus.com/archive/1/517101/100/0/threadedhttps://usn.ubuntu.com/1102-1/https://nvd.nist.gov