CVE-2012-1173

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
04/06/2012
Last modified:
11/04/2025

Description

Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libtiff:libtiff:3.9.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools