Skip to main content

Numeric Errors

CVE-2012-1173

Severity Medium
Score 6.8/10

Summary

Multiple integer overflows in "tiff_getimage.c" in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) "gtTileSeparate" or (2) "gtStripSeparate" function, leading to a heap-based buffer overflow.

  • MEDIUM
  • NETWORK
  • NONE
  • PARTIAL
  • PARTIAL
  • PARTIAL

CWE-189 - Numeric Errors

Weaknesses in this category are related to improper calculation or conversion of numbers.

Advisory Timeline

  • Published