Unrated severityNVD Advisory· Published Jan 19, 2014· Updated Jun 16, 2026
CVE-2013-4231
CVE-2013-4231
Description
Multiple buffer overflows in libtiff before 4.0.3 allow remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) extension block in a GIF image or (2) GIF raster image to tools/gif2tiff.c or (3) a long filename for a TIFF image to tools/rgb2ycbcr.c. NOTE: vectors 1 and 3 are disputed by Red Hat, which states that the input cannot exceed the allocated buffer size.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*range: <=4.0.2
- cpe:2.3:a:libtiff:libtiff:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:libtiff:libtiff:4.0:beta6:*:*:*:*:*:*
- (no CPE)range: <4.0.3
Patches
Vulnerability mechanics
References
9- secunia.com/advisories/54543nvdVendor Advisory
- secunia.com/advisories/54628nvdVendor Advisory
- bugzilla.maptools.org/show_bug.cginvd
- rhn.redhat.com/errata/RHSA-2014-0223.htmlnvd
- www.asmail.be/msg0055359936.htmlnvd
- www.debian.org/security/2013/dsa-2744nvd
- www.openwall.com/lists/oss-security/2013/08/10/2nvd
- www.securityfocus.com/bid/61695nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.