Description
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2004-1304 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. |
References
History
No history.
Subscriptions
Apple
Subscribe
Mac Os X
Subscribe
Mac Os X Server
Subscribe
Avaya
Subscribe
Call Management System Server
Subscribe
Cvlan
Subscribe
Integrated Management
Subscribe
Interactive Response
Subscribe
Intuity Audix Lx
Subscribe
Mn100
Subscribe
Modular Messaging Message Storage Server
Subscribe
Conectiva
Subscribe
Linux
Subscribe
F5
Subscribe
Icontrol Service Manager
Subscribe
Gentoo
Subscribe
Linux
Subscribe
Libtiff
Subscribe
Libtiff
Subscribe
Mandrakesoft
Subscribe
Mandrake Linux
Subscribe
Mandrake Linux Corporate Server
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Sco
Subscribe
Unixware
Subscribe
Sgi
Subscribe
Propack
Subscribe
Sun
Subscribe
Solaris
Subscribe
Sunos
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:46:12.284Z
Reserved: 2004-12-21T00:00:00.000Z
Link: CVE-2004-1307
No data.
Status : Modified
Published: 2004-12-21T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-1307
OpenCVE Enrichment
No data.
Weaknesses
EUVD