← All CVEs

CVE-2012-4564

medium · 6.8

ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow.

6.8
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2012-11-11
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
libtifflibtiff<= 4.0.3
debiandebian_linux6.0
debiandebian_linux7.0
canonicalubuntu_linux8.04
canonicalubuntu_linux10.04
canonicalubuntu_linux11.10
canonicalubuntu_linux12.04
canonicalubuntu_linux12.10
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.3
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
opensuseopensuse11.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-4564