Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0192

31
FAUCET Score

CVE-2011-0192 is a buffer overflow vulnerability in the Fax4Decode function of LibTIFF 3.9.4, affecting products like Apple iTunes on Windows. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through a specially crafted TIFF Internet Fax image file. With a CVSS score of 9.3, it is considered critical due to its network attack vector, medium complexity, and complete impact on confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 10.1.2CPE matchmatch criteria
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:apple:itunes:4.0.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:apple:itunes:4.0.1:*:*:*:*:*:*:*
4.1.0CPE matchmatch criteria
cpe:2.3:a:apple:itunes:4.1.0:*:*:*:*:*:*:*
4.2.0CPE matchmatch criteria
cpe:2.3:a:apple:itunes:4.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.47%
Probability of exploitation in next 30 days
EPSS Percentile
93.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0747 is in the 72nd percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: libtiff-0:3.6.1-17.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libtiff-0:3.8.2-7.el5_6.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libtiff-0:3.9.4-1.el6_0.1
View patch
applevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2011-0192Important

libtiff: buffer overflow in Fax4Decode

Mar 2, 2011

References

blackberry.com / btsc/KB27244
lists.apple.com / archives/security-announce/2011/Mar/msg00000.html
PatchVendor Advisory
lists.apple.com / archives/security-announce/2011//Mar/msg00003.html
lists.apple.com / archives/security-announce/2011//Mar/msg00004.html
lists.apple.com / archives/security-announce/2011//Mar/msg00005.html
lists.apple.com / archives/security-announce/2011/Mar/msg00006.html
lists.apple.com / archives/Security-announce/2011//Oct/msg00001.html
lists.apple.com / archives/Security-announce/2011//Oct/msg00002.html
lists.fedoraproject.org / pipermail/package-announce/2011-April/057763.html
lists.fedoraproject.org / pipermail/package-announce/2011-April/057840.html
lists.fedoraproject.org / pipermail/package-announce/2011-March/055240.html
lists.fedoraproject.org / pipermail/package-announce/2011-March/055683.html
lists.opensuse.org / opensuse-security-announce/2011-04/msg00000.html
lists.opensuse.org / opensuse-security-announce/2011-05/msg00005.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/43585
secunia.com / advisories/43593
secunia.com / advisories/43664
secunia.com / advisories/43934
secunia.com / advisories/44117
secunia.com / advisories/44135
secunia.com / advisories/50726
security.gentoo.org / glsa/glsa-201209-02.xml
slackware.com / security/viewer.php
support.apple.com / kb/HT4554
Vendor Advisory
support.apple.com / kb/HT4564
support.apple.com / kb/HT4565
support.apple.com / kb/HT4566
support.apple.com / kb/HT4581
support.apple.com / kb/HT4999
support.apple.com / kb/HT5001
debian.org / security/2011/dsa-2210
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2011-0318.html
securityfocus.com / bid/46658
securitytracker.com / id
vupen.com / english/advisories/2011/0551
vupen.com / english/advisories/2011/0599
vupen.com / english/advisories/2011/0621
vupen.com / english/advisories/2011/0845
vupen.com / english/advisories/2011/0905
vupen.com / english/advisories/2011/0930
vupen.com / english/advisories/2011/0960