CVE-2013-4243 describes a heap-based buffer overflow in the gif2tiff tool within libtiff versions 4.0.3 and earlier, affecting Debian and other systems utilizing libtiff. This vulnerability, with a CVSS score of 6.8, allows remote attackers to cause a denial of service or potentially execute arbitrary code by supplying crafted GIF image height and width values. While the vulnerability has a moderate attack complexity and potential for partial impact on confidentiality, integrity, and availability, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.3CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* | ||
3.4CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:3.4:*:*:*:*:*:*:* | ||
3.4CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:3.4:beta18:*:*:*:*:*:* | ||
3.4CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:3.4:beta24:*:*:*:*:*:* | ||
3.4CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:3.4:beta28:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.