~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2012-4447

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2012-10-28
2
 
Candidate: CVE-2012-4447
3
 
PublicDate: 2012-10-28
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4447
6
 
 http://www.openwall.com/lists/oss-security/2012/09/25/9
7
 
 https://usn.ubuntu.com/usn/usn-1631-1
8
 
Description:
9
 
 Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows
10
 
 remote attackers to cause a denial of service (application crash) and
11
 
 possibly execute arbitrary code via a crafted TIFF image using the PixarLog
12
 
 Compression format.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
 mdeslaur> as of 2012-10-05, patch may be incomplete. See oss-security
16
 
 mdeslaur> discussion.
17
 
 mdeslaur> incomplete fix in 4.0.2
18
 
Bugs:
19
 
 https://bugzilla.redhat.com/show_bug.cgi?id=860198
20
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688944
21
 
Priority: medium
22
 
Discovered-by:
23
 
Assigned-to: mdeslaur
24
 
 
25
 
Patches_tiff:
26
 
 patch: https://bugzilla.redhat.com/attachment.cgi?id=616925&action=diff&context=patch&collapsed=&headers=1&format=raw
27
 
upstream_tiff: released (4.0.2-4)
28
 
hardy_tiff: released (3.8.2-7ubuntu3.14)
29
 
lucid_tiff: released (3.9.2-2ubuntu0.11)
30
 
natty_tiff: ignored (reached end-of-life)
31
 
oneiric_tiff: released (3.9.5-1ubuntu1.4)
32
 
precise_tiff: released (3.9.5-2ubuntu1.3)
33
 
quantal_tiff: released (4.0.2-1ubuntu2.1)
34
 
raring_tiff: not-affected (4.0.2-4ubuntu1)
35
 
saucy_tiff: not-affected (4.0.2-4ubuntu1)
36
 
trusty_tiff: not-affected (4.0.2-4ubuntu1)
37
 
devel_tiff: not-affected (4.0.2-4ubuntu1)
38
 
 
39
 
Patches_tiff3:
40
 
 patch: https://bugzilla.redhat.com/attachment.cgi?id=616925&action=diff&context=patch&collapsed=&headers=1&format=raw
41
 
 vendor: http://www.debian.org/security/2012/dsa-2561
42
 
upstream_tiff3: needs-triage
43
 
hardy_tiff3: DNE
44
 
lucid_tiff3: DNE
45
 
natty_tiff3: DNE
46
 
oneiric_tiff3: DNE
47
 
precise_tiff3: DNE
48
 
quantal_tiff3: ignored (reached end-of-life)
49
 
raring_tiff3: ignored (reached end-of-life)
50
 
saucy_tiff3: ignored (reached end-of-life)
51
 
trusty_tiff3: DNE
52
 
devel_tiff3: DNE
53