6.8
CVSSv2

CVE-2013-4232

Published: 10/09/2013 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF image.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff 4.0.3

debian debian_linux 6.0

debian debian_linux 7.0

Vendor Advisories

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #742917 tiff: CVE-2013-4243 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Fri, 28 Mar 2014 22:42:02 UTC Severity: important Tags: security Found in version tiff/394-5 Fixed in versions tiff/ ...
Debian Bug report logs - #719303 tiff: CVE-2013-4231 CVE-2013-4232 Package: tiff; Maintainer for tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 10 Aug 2013 13:27:02 UTC Severity: important Tags: security, upstream Fixed in versions tiff/403-2, ti ...
A heap-based buffer overflow and a use-after-free flaw were found in the tiff2pdf tool An attacker could use these flaws to create a specially crafted TIFF file that would cause tiff2pdf to crash or, possibly, execute arbitrary code (CVE-2013-1960, CVE-2013-4232) Multiple buffer overflow flaws were found in the gif2tiff tool An attacker could us ...
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdfc in libtiff 403 allows remote attackers to cause a denial of service (crash) or possible execute arbitrary code via a crafted TIFF image The LZW decompressor in the gif2tiff tool in libtiff 403 and earlier allows context-dependent attackers to cause a deni ...
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdfc in libtiff 403 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF image ...