VYPR
Unrated severityNVD Advisory· Published Jan 19, 2014· Updated Jun 16, 2026

CVE-2013-4231

CVE-2013-4231

Description

Multiple buffer overflows in libtiff before 4.0.3 allow remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) extension block in a GIF image or (2) GIF raster image to tools/gif2tiff.c or (3) a long filename for a TIFF image to tools/rgb2ycbcr.c. NOTE: vectors 1 and 3 are disputed by Red Hat, which states that the input cannot exceed the allocated buffer size.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • LibTIFF/Libtiff11 versions
    cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*range: <=4.0.2
    • cpe:2.3:a:libtiff:libtiff:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:libtiff:libtiff:4.0:beta6:*:*:*:*:*:*
    • (no CPE)range: <4.0.3

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.