---
title: "CVE-2011-0191\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-0191?format=md
keywords: index, follow
---

# CVE-2011-0191

Publication date 2 March 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in
ImageIO in Apple iTunes before 10.2 on Windows and other products, allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted TIFF image with JPEG encoding.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-0191?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tiff | 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Fixed 3.8.2-13ubuntu0.4 |
| 8.04 LTS hardy | Fixed 3.8.2-7ubuntu3.7 |
| 6.06 LTS dapper | Fixed 3.7.4-1ubuntu3.9 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

this doesn't reproduce on 3.9.4 in lucid+

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0191)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-0191)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-0191)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-0191)

### Related Ubuntu Security Notices (USN)

+ [USN-1085-1](https://usn.ubuntu.com/USN-1085-1)
+ tiff vulnerabilities
+ 7 March 2011

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-0191>
