Debian Security Advisory
DSA-2447-1 tiff -- integer overflow
- Date Reported:
- 04 Apr 2012
- Affected Packages:
- tiff
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-1173.
- More information:
-
Alexander Gavrun discovered an integer overflow in the TIFF library in the parsing of the TileSize entry, which could result in the execution of arbitrary code if a malformed image is opened.
For the stable distribution (squeeze), this problem has been fixed in version 3.9.4-5+squeeze4.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your tiff packages.