Executive Summary

Informations
NameCVE-2011-0192First vendor Publication2011-03-03
VendorCveLast vendor Modification2013-05-14

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h. NOTE: some of these details are obtained from third party information.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0192

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Application65

Open Source Vulnerability Database (OSVDB)

idDescription
71257LibTIFF libtiff/tif_fax3.h EXPAND2D() TIFF Image File Handling Overflow

Internal Sources (Detail)

SourceUrl
APPLEhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
http://lists.apple.com/archives/security-announce/2011//Mar/msg00005.html
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html
http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
BIDhttp://www.securityfocus.com/bid/46658
CONFIRMhttp://blackberry.com/btsc/KB27244
http://support.apple.com/kb/HT4554
http://support.apple.com/kb/HT4564
http://support.apple.com/kb/HT4565
http://support.apple.com/kb/HT4566
http://support.apple.com/kb/HT4581
http://support.apple.com/kb/HT4999
http://support.apple.com/kb/HT5001
https://bugzilla.redhat.com/show_bug.cgi?id=678635
DEBIANhttp://www.debian.org/security/2011/dsa-2210
FEDORAhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057763.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057840.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055240.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055683.html
GENTOOhttp://security.gentoo.org/glsa/glsa-201209-02.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:043
REDHAThttp://www.redhat.com/support/errata/RHSA-2011-0318.html
SECTRACKhttp://www.securitytracker.com/id?1025153
SECUNIAhttp://secunia.com/advisories/43585
http://secunia.com/advisories/43593
http://secunia.com/advisories/43664
http://secunia.com/advisories/43934
http://secunia.com/advisories/44117
http://secunia.com/advisories/44135
http://secunia.com/advisories/50726
SLACKWAREhttp://slackware.com/security/viewer.php?l=slackware-security&y=2011&...
VUPENhttp://www.vupen.com/english/advisories/2011/0551
http://www.vupen.com/english/advisories/2011/0599
http://www.vupen.com/english/advisories/2011/0621
http://www.vupen.com/english/advisories/2011/0845
http://www.vupen.com/english/advisories/2011/0905
http://www.vupen.com/english/advisories/2011/0930
http://www.vupen.com/english/advisories/2011/0960

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2013-05-16 17:02:45
  • Multiple Updates
2013-05-10 22:52:25
  • Multiple Updates