CVE-2012-3401: Libtiff

Medium severity, CVSS 6.8. EPSS: 4.1% chance of exploitation in the next 30 days.

The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.

Affected products

  • Libtiff Libtiff: up to and including 4.0.2; version 3.4 only; version 3.5.1 only; version 3.5.2 only; version 3.5.3 only; version 3.5.4 only; …

Published 2012-08-13. Last modified 2026-06-16.