Release date:
Updated on:
Affected Systems:
LibTIFF 3.x
Apple iTunes & lt; 10.1
Unaffected system:
Apple iTunes 1, 10.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46658
Cve id: CVE-2011-0192
LibTiff is an application library for encoding/decoding TIFF image formats.
LibTIFF's "EXPAND2D ()" function has a security vulnerability in implementation. Attackers can exploit this vulnerability to execute arbitrary code in affected applications, resulting in DOS.
This vulnerability is caused by a boundary error in the "EXPAND2D ()" macro of libtiff/tif_fax3.h when decoding a CCITT Group 4 compressed TIFF image. It can be exploited to cause heap buffer overflow through a specially crafted TIFF image.
<* Source: Apple
Link: http://secunia.com/advisories/43593/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apple.com