Buffer overflow in LibTIFF - CVE-2013-4244
Published: September 28, 2013 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image.
Affected software
Amazon Linux AMI
Gentoo Linux
Slackware Linux
tiff (Alpine package)